CVE-2026-44911

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.
References
Link Resource
https://lists.apache.org/thread/wrj3t4k2bwd2cztyp078f5kj3722qfzy Vendor Advisory Mailing List
http://www.openwall.com/lists/oss-security/2026/06/20/4 Third Party Advisory Mailing List
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*

History

23 Jun 2026, 19:55

Type Values Removed Values Added
CPE cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3
References () https://lists.apache.org/thread/wrj3t4k2bwd2cztyp078f5kj3722qfzy - () https://lists.apache.org/thread/wrj3t4k2bwd2cztyp078f5kj3722qfzy - Vendor Advisory, Mailing List
References () http://www.openwall.com/lists/oss-security/2026/06/20/4 - () http://www.openwall.com/lists/oss-security/2026/06/20/4 - Third Party Advisory, Mailing List
First Time Apache nifi
Apache

22 Jun 2026, 10:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/20/4 -

22 Jun 2026, 08:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 08:17

Updated : 2026-06-23 19:55


NVD link : CVE-2026-44911

Mitre link : CVE-2026-44911

CVE.ORG link : CVE-2026-44911


JSON object : View

Products Affected

apache

  • nifi
CWE
CWE-863

Incorrect Authorization