Authorization Flaw in Apache NiFi Affects Configuration Management
CVE-2026-44911

2.3LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
22 June 2026

What is CVE-2026-44911?

A flaw in authorization handling for component configuration verification requests in Apache NiFi versions 1.15.0 through 2.9.0 permits clients with read access to propose configuration changes. These proposed changes can overwrite existing configurations, allowing these users to invoke verification methods with altered settings. Systems that do not enforce different levels of authorization for viewing and modifying component configurations are exposed to this vulnerability. To mitigate this issue, upgrading to Apache NiFi version 2.10.0 or later is essential, as this version requires write access to submit configuration verification requests.

Affected Version(s)

Apache NiFi 1.15.0 <= 2.9.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kaixuan Li from Nanyang Technological University
.