Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-25903
Apache NiFi: restricted permissions not enforced for component updates
Technology
Apache NiFi
CVSS Score
6.6 / 10.0
Affected Versions
1.1.0 to 2.7.2
Upstream Fix
2.8.0
Published
February 17, 2026
OSSeva Coverage
Fixed upstream
Description
Adding a component marked Restricted needs extra permissions, but changing the properties of one already on the canvas did not check them, so a less privileged user could reconfigure it. Installations without separate policies for Restricted components are not affected. Rated high by the NiFi project; NVD scores it 6.6. Fixed in 2.8.0.
Is your Apache NiFi deployment affected?
If you're running 1.1.0 to 2.7.2, you need this patch. Book a discovery call to get covered.