Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-25903

Apache NiFi: restricted permissions not enforced for component updates

Technology

Apache NiFi

CVSS Score

6.6 / 10.0

Affected Versions

1.1.0 to 2.7.2

Upstream Fix

2.8.0

Published

February 17, 2026

OSSeva Coverage

Fixed upstream

Description

Adding a component marked Restricted needs extra permissions, but changing the properties of one already on the canvas did not check them, so a less privileged user could reconfigure it. Installations without separate policies for Restricted components are not affected. Rated high by the NiFi project; NVD scores it 6.6. Fixed in 2.8.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.1.0 to 2.7.2, you need this patch. Book a discovery call to get covered.