Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-44911

Apache NiFi: incorrect authorization for configuration verification requests

Technology

Apache NiFi

CVSS Score

6.3 / 10.0

Affected Versions

1.15.0 to 2.9.0

Upstream Fix

2.10.0

Published

June 22, 2026

OSSeva Coverage

Fixed upstream

Description

Users with only read access to a component could submit configuration verification requests with proposed properties, which override the current configuration and let them run verification methods with other settings. Installations that do not separate read and write access to components are not affected. Rated low by the NiFi project; NVD scores it 6.3. Fixed in 2.10.0, which requires write access.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.15.0 to 2.9.0, you need this patch. Book a discovery call to get covered.