CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7177

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant

Apache Storm Worker Launcher versions before 3.1.0 contain a local privilege escalation vulnerability in which the setuid-root worker-launcher changes directory ownership to an untrusted topology user before reading the command file, allowing that user to modify the file and gain root access. The flaw affects Docker and OCI worker launches in versions 3.0.0 and earlier.

Why it matters: Organizations running Apache Storm 3.0.0 or earlier for distributed stream processing face local privilege escalation risk if untrusted topology users can access worker nodes; upgrade to 3.1.0 or later to patch this root-level exposure.

VendorsDocker
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary