Path Manipulation Vulnerability in Apache NiFi Registry by Apache
CVE-2026-87976
7.2HIGH
What is CVE-2026-87976?
The vulnerability in Apache NiFi Registry versions 0.4.0 through 2.11.0 allows an authenticated user to exploit path manipulation when uploading extension bundles. The default file persistence mechanism inadequately checks directory components in the filesystem path, permitting malicious users to craft manifests that may lead to unauthorized file operations outside the designated storage area. It is crucial to upgrade to Apache NiFi Registry version 2.12.0 or later to effectively mitigate this risk, as the new version enforces path normalization and rejects parent-directory references.
Affected Version(s)
Apache NiFi Registry 0.4.0 <= 2.11.0