Authorization Flaw in Apache NiFi Affects Configuration Property Updates
CVE-2026-25903
What is CVE-2026-25903?
Apache NiFi versions 1.1.0 through 2.7.2 are affected by an authorization flaw that allows less privileged users to modify configuration properties of extension components without proper checks. The issue arises when components annotated with the 'Restricted' annotation, which specify that specific permissions are required, can be altered by users lacking those permissions. While the framework typically enforces authorization at a higher privilege level for adding these components to the flow configuration, it does not adequately check the restricted status during subsequent updates. This flaw can potentially lead to unauthorized changes in flow configurations. To mitigate this risk, it is advised to upgrade to Apache NiFi version 2.8.0 or later.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache NiFi 1.1.0 < 2.8.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved