CVE-2026-44914

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.
References
Link Resource
https://lists.apache.org/thread/ydr34t03xd1n0t9oogpzogjrd5y93838 Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/06/20/6 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*

History

24 Jun 2026, 05:17

Type Values Removed Values Added
References () https://lists.apache.org/thread/ydr34t03xd1n0t9oogpzogjrd5y93838 - Vendor Advisory, Mailing List () https://lists.apache.org/thread/ydr34t03xd1n0t9oogpzogjrd5y93838 - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/06/20/6 - Third Party Advisory, Mailing List () http://www.openwall.com/lists/oss-security/2026/06/20/6 - Mailing List, Third Party Advisory

23 Jun 2026, 19:23

Type Values Removed Values Added
First Time Apache nifi
Apache
CPE cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
References () https://lists.apache.org/thread/ydr34t03xd1n0t9oogpzogjrd5y93838 - () https://lists.apache.org/thread/ydr34t03xd1n0t9oogpzogjrd5y93838 - Vendor Advisory, Mailing List
References () http://www.openwall.com/lists/oss-security/2026/06/20/6 - () http://www.openwall.com/lists/oss-security/2026/06/20/6 - Third Party Advisory, Mailing List

22 Jun 2026, 10:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/20/6 -

22 Jun 2026, 08:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 08:17

Updated : 2026-06-24 05:17


NVD link : CVE-2026-44914

Mitre link : CVE-2026-44914

CVE.ORG link : CVE-2026-44914


JSON object : View

Products Affected

apache

  • nifi
CWE
CWE-862

Missing Authorization