Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-44914
Apache NiFi: restricted permissions not enforced when replacing flow contents
Technology
Apache NiFi
CVSS Score
7.2 / 10.0
Affected Versions
1.12.0 to 2.9.0
Upstream Fix
2.10.0
Published
June 22, 2026
OSSeva Coverage
Fixed upstream
Description
Replacing a Process Group did not check the extra permissions that components marked Restricted require, so a user with general write access could add Restricted components. Installations without specific policies for Restricted components are not affected. Rated high by the NiFi project. Fixed in 2.10.0.
Is your Apache NiFi deployment affected?
If you're running 1.12.0 to 2.9.0, you need this patch. Book a discovery call to get covered.