CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7175

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides

Apache Storm Nimbus versions 3.0.0 before 3.1.0 contain an authorization bypass in the blobstore configuration validation. The vulnerability arises because Nimbus validates the topology blobstore map only at submission time but fails to re-validate when rebalance operations introduce configuration overrides, allowing authorized rebalance callers to bypass restrictions.

Why it matters: Organizations running vulnerable Apache Storm Nimbus versions must patch immediately, as an attacker with rebalance permissions can escalate privileges by modifying blobstore configurations that should be restricted.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary