Authorization Flaw in Apache NiFi Process Group Management
CVE-2026-82561

5.9MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-82561?

Apache NiFi versions 1.5.0 through 2.11.0 experience an authorization flaw in their REST API methods when replacing Process Group contents. This vulnerability allows authenticated users with write access to manipulate or delete components in descendant Process Groups that are under stricter access controls. The inadequate authorization checks mean these users can bind components without appropriate permissions for the associated Controller Services and Parameter Contexts, leading to potential security breaches in systems employing component-level authorization policies. Users are advised to upgrade to version 2.12.0 to implement enhanced validation measures that enforce proper authorization across all related components.

Affected Version(s)

Apache NiFi 1.5.0 <= 2.11.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.