Authorization Flaw in Apache NiFi Affects Configuration Management
CVE-2026-44911
2.3LOW
What is CVE-2026-44911?
A flaw in authorization handling for component configuration verification requests in Apache NiFi versions 1.15.0 through 2.9.0 permits clients with read access to propose configuration changes. These proposed changes can overwrite existing configurations, allowing these users to invoke verification methods with altered settings. Systems that do not enforce different levels of authorization for viewing and modifying component configurations are exposed to this vulnerability. To mitigate this issue, upgrading to Apache NiFi version 2.10.0 or later is essential, as this version requires write access to submit configuration verification requests.
Affected Version(s)
Apache NiFi 1.15.0 <= 2.9.0
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kaixuan Li from Nanyang Technological University