CVE-2026-82561
Apache NiFi: missing authorization for components referenced in flow update methods
Technology
Apache NiFi
CVSS Score
6.5 / 10.0
Affected Versions
1.5.0 to 2.11.0
Upstream Fix
2.12.0
Published
September 16, 2026
OSSeva Coverage
Fixed upstream
Description
REST API methods that replace a Process Group's contents, including versioned flow update and rebase, checked only read and write on the Process Group. A user with write access to it could change or remove components in more tightly controlled child groups and bind components to Controller Services and Parameter Contexts they were not authorised for. It applies only where component-level policies are used. Rated medium by the NiFi project. Fixed in 2.12.0.
Is your Apache NiFi deployment affected?
If you're running 1.5.0 to 2.11.0, you need this patch. Book a discovery call to get covered.