Description
Description

Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance
operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that
validation, so a caller authorised to rebalance a topology could introduce a blobstore map entry naming a
blob whose ACL does not grant them access. Supervisors localise whatever key the map names, placing the
blob's contents into the topology's working directory.

The same advisory covers `listBlobs`, which performed no authorization check and passed no subject, unlike
the neighbouring `getBlobMeta` and `beginBlobDownload` operations. It therefore returned every key in the
blobstore to any caller able to reach the Nimbus Thrift port, which provides the key names that make the
above practical. On its own the disclosure is metadata only.

Mitigation

Upgrade to 3.1.0, where rebalance configuration overrides are validated exactly as submission-time
configuration is, against the rebalancing caller, and where `listBlobs` applies the configured
authorization.

Users who cannot upgrade immediately should restrict rebalance rights to trusted principals, keeping in mind
that membership of a topology's `topology.users` or `topology.groups` confers them.

Credit

The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to Storm Blobstore data
Action: Immediate Patch
AI Analysis

Impact

The flaw allows a user who can rebalance a topology to insert a blobstore map entry that references a blob whose access control list does not grant that user read permission, so the blob’s contents are inadvertently copied into the topology’s working directory. In addition, the listBlobs operation performs no authorization check and can be invoked by any caller that can reach the Nimbus Thrift port, creating a metadata leak of every blob key that can be used to retrieve unwanted data. Together these issues enable privileged users to access or exfiltrate internal Storm configuration and data stored in the blobstore.

Affected Systems

Apache Storm Nimbus installations that have not applied the 3.1.0 or later updates are affected. The vulnerability exists in all earlier versions of the Nimbus component and can impact any deployment that relies on the default configuration of the rebalance operation and blob listing APIs.

Risk and Exploitability

The CVSS score of 8.1 denotes a high severity vulnerability. Although the EPSS score is less than 1 %, the issue is not listed in CISA’s KEV catalog. The likely attack vector is remote; an attacker only needs to reach the Nimbus Thrift service to exploit listBlobs or to use the rebalance operation as a privileged user. Once the attack is launched, the attacker can read arbitrary blob contents, potentially leading to data compromise or further lateral movement if the blob contains configuration or code useful to an attacker. The lack of re‑validation of rebalance configuration overrides makes exploitation straightforward for a correctly privileged user.

Generated by OpenCVE AI on September 21, 2026 at 00:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Storm Nimbus to version 3.1.0 or later, which adds validation of rebalance configuration overrides against the rebalancer’s permissions and restricts listBlobs to authorized callers.
  • Restrict rebalance permissions by granting the rebalance operation only to trusted principals and avoid assigning rebalance rights to users who do not require that privilege.
  • Limit access to the Nimbus Thrift port so that only trusted network segments or hosts can perform rebalance or listBlobs operations, until the vulnerability is fully patched.

Generated by OpenCVE AI on September 21, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validation, so a caller authorised to rebalance a topology could introduce a blobstore map entry naming a blob whose ACL does not grant them access. Supervisors localise whatever key the map names, placing the blob's contents into the topology's working directory. The same advisory covers `listBlobs`, which performed no authorization check and passed no subject, unlike the neighbouring `getBlobMeta` and `beginBlobDownload` operations. It therefore returned every key in the blobstore to any caller able to reach the Nimbus Thrift port, which provides the key names that make the above practical. On its own the disclosure is metadata only. Mitigation Upgrade to 3.1.0, where rebalance configuration overrides are validated exactly as submission-time configuration is, against the rebalancing caller, and where `listBlobs` applies the configured authorization. Users who cannot upgrade immediately should restrict rebalance rights to trusted principals, keeping in mind that membership of a topology's `topology.users` or `topology.groups` confers them. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Title Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T20:03:24.941Z

Reserved: 2026-08-29T10:23:29.749Z

Link: CVE-2026-82432

cve-icon Vulnrichment

Updated: 2026-09-14T14:13:26.412Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:10.187

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-82432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses