Junglewise Threat Intelligence

CVE-2026-82431: Apache Storm SimpleACLAuthorizer authorization bypass

CVE-2026-82431 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Technologies: Apache Storm. Vendors: Apache.

Executive brief

Apache Storm is a distributed stream processing framework used to ingest and process large volumes of real-time data. A flaw in the authorization system allows any authenticated user to perform restricted administrative operations—including topology submission and configuration access—when cluster access is controlled by group membership alone. This means deployments following the documented security guidance could believe they are protected when they are completely unrestricted.

Technical details

The vulnerability is an authorization bypass in SimpleACLAuthorizer that returns early when nimbus.users is empty, before evaluating nimbus.groups. This causes group-based access restrictions to be silently ignored, permitting all authenticated principals to execute user-level operations (submitTopology, beginFileUpload, getNimbusConf). The attack requires authentication but no further preconditions; the vulnerability silently bypasses controls documented as a supported restriction mechanism. Patch to version 3.1.0 to fix; affected versions require either upgrading or as a workaround populating nimbus.users to force group evaluation.

Affected products

  • Apache Storm before 3.1.0

Timeline

  • 2026-09-14: disclosed

Related threats