Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-87976

Apache NiFi Registry: path manipulation when storing extension bundles

Technology

Apache NiFi Registry

CVSS Score

8.1 / 10.0

Affected Versions

NiFi Registry 0.4.0 to 2.11.0

Upstream Fix

NiFi Registry 2.12.0

Published

September 16, 2026

OSSeva Coverage

Fixed upstream

Description

The default file persistence provider used the group, artifact and version coordinates from an uploaded NAR manifest as path components without rejecting parent-directory names. A user allowed to write and delete bundles in a bucket could upload a crafted NAR and cause file operations outside the storage directory. Rated high by the NiFi project. Fixed in NiFi Registry 2.12.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi Registry deployment affected?

If you're running NiFi Registry 0.4.0 to 2.11.0, you need this patch. Book a discovery call to get covered.