Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-87976
Apache NiFi Registry: path manipulation when storing extension bundles
Technology
Apache NiFi Registry
CVSS Score
8.1 / 10.0
Affected Versions
NiFi Registry 0.4.0 to 2.11.0
Upstream Fix
NiFi Registry 2.12.0
Published
September 16, 2026
OSSeva Coverage
Fixed upstream
Description
The default file persistence provider used the group, artifact and version coordinates from an uploaded NAR manifest as path components without rejecting parent-directory names. A user allowed to write and delete bundles in a bucket could upload a crafted NAR and cause file operations outside the storage directory. Rated high by the NiFi project. Fixed in NiFi Registry 2.12.0.
Is your Apache NiFi Registry deployment affected?
If you're running NiFi Registry 0.4.0 to 2.11.0, you need this patch. Book a discovery call to get covered.