Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-44914

Apache NiFi: restricted permissions not enforced when replacing flow contents

Technology

Apache NiFi

CVSS Score

7.2 / 10.0

Affected Versions

1.12.0 to 2.9.0

Upstream Fix

2.10.0

Published

June 22, 2026

OSSeva Coverage

Fixed upstream

Description

Replacing a Process Group did not check the extra permissions that components marked Restricted require, so a user with general write access could add Restricted components. Installations without specific policies for Restricted components are not affected. Rated high by the NiFi project. Fixed in 2.10.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.12.0 to 2.9.0, you need this patch. Book a discovery call to get covered.