CVE-2026-82432: CWE-863 Incorrect Authorization in Apache Software Foundation Apache Storm Nimbus
CVE-2026-82432 is an authorization vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It allows an authorized user with rebalance privileges to introduce unauthorized blobstore map entries referencing blobs they do not have access to. Additionally, the listBlobs operation lacks authorization checks, exposing metadata about all blobs to any caller able to reach the Nimbus Thrift port. The issue is fixed in version 3.1.0 by enforcing authorization checks on rebalance configuration overrides and listBlobs calls.
AI Analysis
Technical Summary
Apache Storm Nimbus validated the topology.blobstore.map configuration only at submission time against the caller's authorization. However, during the rebalance operation, configuration overrides were accepted without revalidating authorization, allowing a caller authorized to rebalance a topology to add blobstore map entries naming blobs without proper ACL permissions. Supervisors would localize these blobs into the topology's working directory, potentially exposing unauthorized data. Furthermore, the listBlobs operation did not perform any authorization checks and returned all blob keys to any caller able to access the Nimbus Thrift port, exposing metadata. The vulnerability is addressed in Apache Storm 3.1.0 by applying the same authorization validation during rebalance and enforcing authorization on listBlobs.
Potential Impact
An attacker with rebalance privileges on a topology could introduce unauthorized blob references, potentially causing supervisors to expose blob contents they should not access. Additionally, any caller able to reach the Nimbus Thrift port could retrieve metadata about all blobs via listBlobs, revealing sensitive information about stored blobs. This could lead to unauthorized data exposure within the Apache Storm environment.
Mitigation Recommendations
Upgrade Apache Storm Nimbus to version 3.1.0 or later, where rebalance configuration overrides are validated against the caller's authorization and listBlobs enforces authorization checks. For users unable to upgrade immediately, restrict rebalance privileges to trusted principals only, considering that membership in a topology's topology.users or topology.groups grants rebalance rights.
CVE-2026-82432: CWE-863 Incorrect Authorization in Apache Software Foundation Apache Storm Nimbus
Description
CVE-2026-82432 is an authorization vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It allows an authorized user with rebalance privileges to introduce unauthorized blobstore map entries referencing blobs they do not have access to. Additionally, the listBlobs operation lacks authorization checks, exposing metadata about all blobs to any caller able to reach the Nimbus Thrift port. The issue is fixed in version 3.1.0 by enforcing authorization checks on rebalance configuration overrides and listBlobs calls.
Affected software
Apache Software Foundation
Apache Storm Nimbus
pkg:maven/Apache Software Foundation/org.apache.storm:storm-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Storm Nimbus validated the topology.blobstore.map configuration only at submission time against the caller's authorization. However, during the rebalance operation, configuration overrides were accepted without revalidating authorization, allowing a caller authorized to rebalance a topology to add blobstore map entries naming blobs without proper ACL permissions. Supervisors would localize these blobs into the topology's working directory, potentially exposing unauthorized data. Furthermore, the listBlobs operation did not perform any authorization checks and returned all blob keys to any caller able to access the Nimbus Thrift port, exposing metadata. The vulnerability is addressed in Apache Storm 3.1.0 by applying the same authorization validation during rebalance and enforcing authorization on listBlobs.
Potential Impact
An attacker with rebalance privileges on a topology could introduce unauthorized blob references, potentially causing supervisors to expose blob contents they should not access. Additionally, any caller able to reach the Nimbus Thrift port could retrieve metadata about all blobs via listBlobs, revealing sensitive information about stored blobs. This could lead to unauthorized data exposure within the Apache Storm environment.
Mitigation Recommendations
Upgrade Apache Storm Nimbus to version 3.1.0 or later, where rebalance configuration overrides are validated against the caller's authorization and listBlobs enforces authorization checks. For users unable to upgrade immediately, restrict rebalance privileges to trusted principals only, considering that membership in a topology's topology.users or topology.groups grants rebalance rights.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-29T10:23:29.749Z
- State
- PUBLISHED
Threat ID: 6aa8057255bf5e2cf52f81c7
Added to database: 09/14/2026, 14:32:18 UTC
Last enriched: 09/14/2026, 14:48:01 UTC
Last updated: 09/14/2026, 15:41:27 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.