Path Manipulation Vulnerability in Apache NiFi Registry by Apache
CVE-2026-87976

7.2HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-87976?

The vulnerability in Apache NiFi Registry versions 0.4.0 through 2.11.0 allows an authenticated user to exploit path manipulation when uploading extension bundles. The default file persistence mechanism inadequately checks directory components in the filesystem path, permitting malicious users to craft manifests that may lead to unauthorized file operations outside the designated storage area. It is crucial to upgrade to Apache NiFi Registry version 2.12.0 or later to effectively mitigate this risk, as the new version enforces path normalization and rejects parent-directory references.

Affected Version(s)

Apache NiFi Registry 0.4.0 <= 2.11.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lichoin
.