CVE-2026-82431 Details
Description
Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.users` unset, therefore received no restriction at all: every authenticated principal was permitted every user-level operation, including `submitTopology`, `beginFileUpload` and `getNimbusConf`. `docs/SECURITY.md` presents `nimbus.groups` as a supported way to lock down a cluster, so a deployment following the documentation could believe it was restricted while it was not. The failure is silent; nothing in the logs or the configuration indicates that the group list is being ignored. Both lists left empty continues to mean that no restriction is configured, which is the shipped default and is unchanged. Mitigation Upgrade to 3.1.0, where `nimbus.groups` is evaluated whether or not `nimbus.users` is set. Users who cannot upgrade immediately should additionally populate `nimbus.users` with the intended principals, since a non-empty user list causes the group list to be evaluated on affected versions. Operators should review Nimbus access logs for operations by principals outside the intended groups. Note that after upgrading, a cluster configured with `nimbus.groups` alone becomes restrictive for the first time. This includes `NimbusClient`, which calls `getLeader` on every connection, so clients outside the configured groups will begin to be refused. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
A vulnerability exists in Apache Storm Client versions 3.0.0 prior to 3.1.0, within the `SimpleACLAuthorizer` component. The issue arises when `nimbus.groups` is configured without `nimbus.users`. In such cases, the authorizer evaluates user-level commands by returning early if `nimbus.users` is empty, before considering `nimbus.groups`. This oversight allows every authenticated principal to perform user-level operations, such as `submitTopology`, `beginFileUpload`, and `getNimbusConf`, without any restrictions. The problem is exacerbated by the lack of logging or configuration indicators that the group list is being ignored, leading to a silent failure. Consequently, operators who rely solely on group-based access control may mistakenly believe their clusters are secure when they are not.
To address this vulnerability, users should upgrade to Apache Storm Client version 3.1.0 or later, where the `nimbus.groups` configuration is properly evaluated regardless of the `nimbus.users` setting. For those unable to upgrade immediately, it is recommended to populate the `nimbus.users` list with the intended principals, as a non-empty user list will trigger the evaluation of the group list on affected versions. After upgrading, operators should review Nimbus access logs for any operations performed by principals outside the designated groups, as the change will make clusters with `nimbus.groups` configured more restrictive for the first time.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/13/11 | CVE | AdvisoryMailing ListRemedy |
| https://lists.apache.org/thread/s335qxb6woqb35ho3fpq7toytsz1gpts | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Storm | >= 3.0.0, < 3.1.0 (semver) |
CPE
Remediation
| |
| Apache Storm Client | >= 3.0.0, < 3.1.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | CVE Modified | CVE |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion