ID:13049 - Exploit for Missing Authorization in Apache Nifi - CVE-2026-39816
Published: September 4, 2026
Apache Nifi
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in TinkerpopClientService when configuring bytecode submission for the script submission type. A remote user can configure the service to execute Groovy script code to execute arbitrary code.
Only installations that use fine-grained authorization and have the optional nifi-other-graph-services-nar extension installed are vulnerable.