Description
Description

Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a
server-side path and opened it directly, without checking that it referred to a file the caller had
actually uploaded. The intended flow is that a client first calls `beginFileUpload`, which returns a path
inside the Nimbus inbox, and uploads the jar in chunks to that location; nothing bound submission to that
flow, and the `uploaders` map populated by `beginFileUpload` was never consulted at submit time.

An authenticated user with topology submission rights could therefore submit any path readable by the
Nimbus daemon user as their topology jar. Nimbus copied the file into the topology's jar blob, and the
blob ACL grants the submitting subject read access, so the contents could then be retrieved with the
ordinary blob download RPCs. Candidate targets include the Nimbus Kerberos keytab, Thrift and UI TLS
private keys, and `storm.yaml` with the ZooKeeper authentication payload. Possession of the Nimbus keytab
turns an ordinary tenant into a cluster administrator.

In a deployment configured as the documentation recommends, submission is available to every
authenticated principal when `nimbus.users` is unset, so no elevated privilege is required.

Mitigation

Upgrade to 3.1.0, where the submitted location is canonicalised and must resolve inside the Nimbus inbox.

Users who cannot upgrade immediately should restrict topology submission to trusted principals via
`nimbus.users` or `nimbus.groups`, and should treat any file readable by the Nimbus daemon user as
potentially exposed to submitters: rotate the Nimbus keytab and any TLS private keys or ZooKeeper
credentials reachable from that account. Local mode is unaffected.


Credit

Independently reported to the Apache Storm PMC by n0mi1k, with a proof of concept.

Also found by the ASF using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privileged Escalation via Arbitrary File Read
Action: Immediate Patch
AI Analysis

Impact

Apache Storm Nimbus accepts the uploadedJarLocation argument in submitTopology as a server‑side path without verifying that the file was first uploaded by the user. to point the argument at any file readable by the Nimbus daemon account. The file is then copied into the topology jar blob and made accessible to the submitting user through normal blob download RPCs. As a result, attackers can read sensitive configuration files such as the Nimbus Kerberos keytab, TLS private keys, and ZooKeeper authentication data, effectively giving them cluster‑wide administrative privileges. The vulnerability is a classic example of CWE‑22: Path Traversal or Arbitrary File Read.

Affected Systems

The flaw affects all Apache Storm Nimbus deployments that are not updated to version 3.1.0 or later. Systems running earlier releases, particularly those that leave nimbus.users unset and therefore permit any authenticated principal to submit topologies, are vulnerable. The remedy is to upgrade to 3.1.0 or newer where the submitted location is canonicalised and required to resolve inside the Nimbus inbox.

Risk and Exploitability

This vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is <1%, indicating a very low exploitation probability, and the lack of a KEV listing suggests no widespread exploitation yet. An attacker only needs to be an authenticated user with topology submission capabilities, which may be common when nimbus.users or nimbus.groups are not configured. Once exploited, the attacker can gain critical credentials and become a cluster administrator. The risk is therefore moderate to significant, especially in environments where the default configuration permits unrestricted topology submission.

Generated by OpenCVE AI on September 21, 2026 at 00:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Apache Storm 3.1.0 or newer to enforce canonicalization of the submitted jar location.
  • If an upgrade is not yet possible, restrict topology submission rights to trusted users by configuring nimbus.users or nimbus.groups to limit who may call submitTopology.
  • Rotate any Nimbus Kerberos keytab, TLS private keys, or ZooKeeper credentials that are readable by the Nimbus daemon account, and treat all such files as potentially exposed by submitters.

Generated by OpenCVE AI on September 21, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. The intended flow is that a client first calls `beginFileUpload`, which returns a path inside the Nimbus inbox, and uploads the jar in chunks to that location; nothing bound submission to that flow, and the `uploaders` map populated by `beginFileUpload` was never consulted at submit time. An authenticated user with topology submission rights could therefore submit any path readable by the Nimbus daemon user as their topology jar. Nimbus copied the file into the topology's jar blob, and the blob ACL grants the submitting subject read access, so the contents could then be retrieved with the ordinary blob download RPCs. Candidate targets include the Nimbus Kerberos keytab, Thrift and UI TLS private keys, and `storm.yaml` with the ZooKeeper authentication payload. Possession of the Nimbus keytab turns an ordinary tenant into a cluster administrator. In a deployment configured as the documentation recommends, submission is available to every authenticated principal when `nimbus.users` is unset, so no elevated privilege is required. Mitigation Upgrade to 3.1.0, where the submitted location is canonicalised and must resolve inside the Nimbus inbox. Users who cannot upgrade immediately should restrict topology submission to trusted principals via `nimbus.users` or `nimbus.groups`, and should treat any file readable by the Nimbus daemon user as potentially exposed to submitters: rotate the Nimbus keytab and any TLS private keys or ZooKeeper credentials reachable from that account. Local mode is unaffected. Credit Independently reported to the Apache Storm PMC by n0mi1k, with a proof of concept. Also found by the ASF using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Title Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location
Weaknesses CWE-22
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:53:45.290Z

Reserved: 2026-08-29T10:01:40.256Z

Link: CVE-2026-82426

cve-icon Vulnrichment

Updated: 2026-09-14T14:13:17.028Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:09.410

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-82426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')