Authorization Flaw in Apache NiFi Affects Configuration Property Updates
CVE-2026-25903
What is CVE-2026-25903?
Apache NiFi versions 1.1.0 through 2.7.2 are affected by an authorization flaw that allows less privileged users to modify configuration properties of extension components without proper checks. The issue arises when components annotated with the 'Restricted' annotation, which specify that specific permissions are required, can be altered by users lacking those permissions. While the framework typically enforces authorization at a higher privilege level for adding these components to the flow configuration, it does not adequately check the restricted status during subsequent updates. This flaw can potentially lead to unauthorized changes in flow configurations. To mitigate this risk, it is advised to upgrade to Apache NiFi version 2.8.0 or later.
Affected Version(s)
Apache NiFi 1.1.0 < 2.8.0