CVE-2026-82429
Deferred Deferred - Pending Action

Symbolic Link Race Condition in Apache Storm Worker Launcher

Vulnerability report for CVE-2026-82429, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Apache Software Foundation

Description

Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid of 0. Both syscalls re-resolve the path at the time of the call, after FTS has classified the entry, and the trees being walked are owned and writable by the untrusted topology user. A tenant running code on a supervisor node could therefore replace an intermediate directory component with a symbolic link between classification and the privileged operation, redirecting the root-owned `lchown` or `chmod` at an arbitrary file on the host. The operation is repeatable at will, since crashing a worker forces a relaunch and blob updates re-run the walk, so a failed attempt costs the attacker nothing. This crosses the boundary that `supervisor.run.worker.as.user` and container isolation are intended to enforce. It is the same defect class as the Hadoop container-executor issues from which this code derives. Mitigation Upgrade to 3.1.0, where the privileged walk operates on file descriptors it has already stat'd rather than on pathnames re-resolved at call time. Users who cannot upgrade immediately should not run untrusted topology code on supervisors configured with `supervisor.run.worker.as.user`, since the launcher is the boundary being crossed. Note that the launcher must be rebuilt and reinstalled after upgrading; replacing the Java artifacts alone is not sufficient. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache storm 3.1.0
apache storm to 3.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a setuid-root binary called worker-launcher that changes ownership and permissions of directories while running with root privileges. It uses FTS to traverse directories and calls lchown and chmod on each entry. An attacker can replace a directory with a symbolic link between the directory check and the privileged operation, redirecting the root-owned operations to arbitrary files on the host. This allows untrusted code to bypass intended isolation boundaries.

Detection Guidance

This vulnerability involves a race condition in the setuid-root worker-launcher binary where symbolic links can redirect privileged operations. Detection requires checking for vulnerable versions of Apache Storm and examining worker directory permissions. No specific commands are provided in the context, but monitoring for unexpected file ownership changes or permission modifications in worker directories may indicate exploitation.

Impact Analysis

If you run untrusted topology code on a supervisor node with the vulnerable setup, an attacker could gain root access to your system. They could modify or delete critical files, install malware, or escalate privileges beyond intended container isolation. The attack is repeatable and low-cost for the attacker, making it a serious risk.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating confidentiality and integrity requirements in GDPR and HIPAA. It undermines access controls and audit mechanisms, potentially resulting in non-compliance with data protection regulations and legal penalties.

Mitigation Strategies
  • Upgrade to Apache Storm version 3.1.0 or later where the issue is fixed.
  • If immediate upgrade is not possible, avoid running untrusted topology code on supervisors configured with supervisor.run.worker.as.user.
  • Rebuild and reinstall the launcher after upgrading; replacing Java artifacts alone is insufficient.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82429. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart