Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-82561

Apache NiFi: missing authorization for components referenced in flow update methods

Technology

Apache NiFi

CVSS Score

6.5 / 10.0

Affected Versions

1.5.0 to 2.11.0

Upstream Fix

2.12.0

Published

September 16, 2026

OSSeva Coverage

Fixed upstream

Description

REST API methods that replace a Process Group's contents, including versioned flow update and rebase, checked only read and write on the Process Group. A user with write access to it could change or remove components in more tightly controlled child groups and bind components to Controller Services and Parameter Contexts they were not authorised for. It applies only where component-level policies are used. Rated medium by the NiFi project. Fixed in 2.12.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.5.0 to 2.11.0, you need this patch. Book a discovery call to get covered.