Description
Description

`SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty,
before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving
`nimbus.users` unset, therefore received no restriction at all: every authenticated principal was permitted
every user-level operation, including `submitTopology`, `beginFileUpload` and `getNimbusConf`.

`docs/SECURITY.md` presents `nimbus.groups` as a supported way to lock down a cluster, so a deployment
following the documentation could believe it was restricted while it was not. The failure is silent; nothing
in the logs or the configuration indicates that the group list is being ignored.

Both lists left empty continues to mean that no restriction is configured, which is the shipped default and
is unchanged.

Mitigation

Upgrade to 3.1.0, where `nimbus.groups` is evaluated whether or not `nimbus.users` is set.

Users who cannot upgrade immediately should additionally populate `nimbus.users` with the intended
principals, since a non-empty user list causes the group list to be evaluated on affected versions.
Operators should review Nimbus access logs for operations by principals outside the intended groups.

Note that after upgrading, a cluster configured with `nimbus.groups` alone becomes restrictive for the first
time. This includes `NimbusClient`, which calls `getLeader` on every connection, so clients outside the
configured groups will begin to be refused.

Credit

The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass permitting any authenticated principal to perform privileged actions
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in Apache Storm's SimpleACLAuthorizer causes the ACL check to return early when the nimbus.users list is empty, ignoring the group list set in nimbus.groups. An operator who configures access control solely by group without specifying any users therefore experiences no restriction-level permissions, including the ability to submit topologies, upload files, and retrieve Nimbus configuration. This flaw enables an attacker who can authenticate with valid credentials to execute any privileged operation and effectively gain full control over the cluster. Based on the description, it is inferred that the attacker can manipulate topological deployment and file uploads, thus impacting confidentiality, integrity, and availability.

Affected Systems

Apache Storm Client deployments that have nimbus.groups configured but leave nimbus.users unset are affected. All releases prior to 3.1.0 contain the logic error; version 3.1.0 and later correct the evaluation so that group restrictions are applied regardless of the user list.

Risk and Exploitability

The CVSS score of 9.8 reflects a high severity, authenticated-level threat; an attacker only needs to obtain or reuse a valid principal name. The EPSS score is less than 1 %, indicating that currently no widespread exploitation is observed, but the absence of a KEV listing does not diminish the critical severity. The bug can be exploited remotely via any Storm client that authenticates to Nimbus, giving the attacker full cluster access. Based on the description, it is inferred that the likely attack vector involves a remote client authenticating to Nimbus, as the logic flaw is triggered when credentials are presented to the Storm client.

Generated by OpenCVE AI on September 21, 2026 at 00:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Storm Client to version 3.1.0 or later, which fixes the authorization check and applies group restrictions independent of the user list.
  • If an upgrade cannot be performed immediately, populate the nimbus.users property with the intended principals; a non‑empty user list forces the server to evaluate group restrictions even on vulnerable versions.
  • Review Nimbus access logs for operations performed by principals outside the configured groups and adjust policies or revoke credentials as necessary.

Generated by OpenCVE AI on September 21, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.users` unset, therefore received no restriction at all: every authenticated principal was permitted every user-level operation, including `submitTopology`, `beginFileUpload` and `getNimbusConf`. `docs/SECURITY.md` presents `nimbus.groups` as a supported way to lock down a cluster, so a deployment following the documentation could believe it was restricted while it was not. The failure is silent; nothing in the logs or the configuration indicates that the group list is being ignored. Both lists left empty continues to mean that no restriction is configured, which is the shipped default and is unchanged. Mitigation Upgrade to 3.1.0, where `nimbus.groups` is evaluated whether or not `nimbus.users` is set. Users who cannot upgrade immediately should additionally populate `nimbus.users` with the intended principals, since a non-empty user list causes the group list to be evaluated on affected versions. Operators should review Nimbus access logs for operations by principals outside the intended groups. Note that after upgrading, a cluster configured with `nimbus.groups` alone becomes restrictive for the first time. This includes `NimbusClient`, which calls `getLeader` on every connection, so clients outside the configured groups will begin to be refused. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Title Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T20:01:54.073Z

Reserved: 2026-08-29T10:21:15.109Z

Link: CVE-2026-82431

cve-icon Vulnrichment

Updated: 2026-09-14T15:13:50.464Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:10.053

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-82431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses