Skip to main content

CVE-2026-82430: CWE-367 Time-of-check time-of-use (TOCTOU) race condition in Apache Software Foundation Apache Storm Worker Launcher

0
High
Published: 09/14/2026 (09/14/2026, 15:32:49 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Storm Worker Launcher

Description

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wrote into that same directory. The file is opened without `O_NOFOLLOW` and without re-verifying its owner, so between the ownership change and the read the tenant can replace its contents. For the Docker path the parsed command is executed with real uid 0, and the command sanitiser is not a privilege boundary: it admits `-v` with an arbitrary source, `--device`, `--cap-add`, `--security-opt`, `--user` and `--net`, and copies positional arguments through verbatim. A rewritten file therefore yields an attacker-authored, root-equivalent container invocation with the host filesystem available. For the OCI path the same rewrite window applies, and mount validation is structural only, with no source or destination allow-list, so arbitrary host paths can be bind-mounted read-write into the container. The `username` field of the command file is likewise attacker-settable and is checked only against non-root and minimum-uid rules, permitting execution as another tenant's uid. Mitigation Upgrade to 3.1.0, where the command file is validated before the ownership change and re-verified on open, and where mount sources and destinations are constrained by configuration. Users who cannot upgrade immediately should disable Docker and OCI worker isolation, or restrict topology submission on affected supervisors to trusted principals. Note that the launcher must be rebuilt and reinstalled after upgrading. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Apache Software Foundation

Apache Storm Worker Launcher

Affected versions
>=3.0.0 <3.1.0
Apache Software Foundation/org.apache.storm:storm-core
pkg:maven/Apache Software Foundation/org.apache.storm:storm-core
Affected versions
>=3.0.0 <3.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 14:48:12 UTC

Technical Analysis

The Apache Storm Worker Launcher has a TOCTOU race condition (CWE-367) when launching Docker or OCI workers. The setuid-root worker-launcher changes ownership of the worker directory to the untrusted topology user before reading the command file, which is opened without O_NOFOLLOW and without re-verifying ownership. This allows an attacker to replace the command file contents between the ownership change and the read. For Docker, this leads to execution of attacker-crafted commands with real uid 0, enabling root-equivalent container invocation with host filesystem access. For OCI, arbitrary host paths can be bind-mounted read-write, and the username field can be set to execute as another tenant's uid. The vulnerability affects Apache Storm versions >=3.0.0 and <3.1.0. The issue is fixed in version 3.1.0 by validating the command file before ownership changes and restricting mount configurations. Users unable to upgrade should disable Docker and OCI worker isolation or restrict topology submission to trusted users. The launcher must be rebuilt and reinstalled after upgrading.

Potential Impact

Successful exploitation allows an attacker with topology submission privileges to execute arbitrary commands with root-equivalent privileges inside Docker containers or to mount arbitrary host paths read-write inside OCI containers. This can lead to full host filesystem access and execution as other tenant UIDs, severely compromising the host and multi-tenant environment security.

Mitigation Recommendations

Upgrade to Apache Storm version 3.1.0, which fixes the vulnerability by validating the command file before changing ownership and constraining mount sources and destinations. After upgrading, rebuild and reinstall the worker-launcher. For users unable to upgrade immediately, disable Docker and OCI worker isolation or restrict topology submission on affected supervisors to trusted principals.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-29T10:18:19.828Z
State
PUBLISHED

Threat ID: 6aa8057055bf5e2cf52f81bf

Added to database: 09/14/2026, 14:32:16 UTC

Last enriched: 09/14/2026, 14:48:12 UTC

Last updated: 09/15/2026, 04:29:38 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses