A AegiFlow
LOWCVSS 2.3EPSS 0.5%

CVE-2026-44911

Apache NiFi allows read-only users to submit component configuration verification request

Published
2026-06-22
Modified
2026-09-11
EPSS percentile
42%
Aliases
GHSA-qvj8-gwpm-4x49
Sources
github-advisory

Summary

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.apache.nifi:nifi-web-api2.10.0

Remediation: Upgrade to 2.10.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.