Authorization Flaw in Apache NiFi Process Group Management
CVE-2026-82561
What is CVE-2026-82561?
Apache NiFi versions 1.5.0 through 2.11.0 experience an authorization flaw in their REST API methods when replacing Process Group contents. This vulnerability allows authenticated users with write access to manipulate or delete components in descendant Process Groups that are under stricter access controls. The inadequate authorization checks mean these users can bind components without appropriate permissions for the associated Controller Services and Parameter Contexts, leading to potential security breaches in systems employing component-level authorization policies. Users are advised to upgrade to version 2.12.0 to implement enhanced validation measures that enforce proper authorization across all related components.
Affected Version(s)
Apache NiFi 1.5.0 <= 2.11.0