ID:13049 - Exploit for Missing Authorization in Apache Nifi - CVE-2026-39816

 
Main Vulnerability Database Exploits ID:13049 - Exploit for Missing Authorization in Apache Nifi - CVE-2026-39816

ID:13049 - Exploit for Missing Authorization in Apache Nifi - CVE-2026-39816

Published: September 4, 2026


Vulnerability identifier: #VU145318
Vulnerability risk: Medium
CVE-ID: CVE-2026-39816
CWE-ID: CWE-862
Exploitation vector: Remote access
Vulnerable software:
Apache Nifi

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in TinkerpopClientService when configuring bytecode submission for the script submission type. A remote user can configure the service to execute Groovy script code to execute arbitrary code.

Only installations that use fine-grained authorization and have the optional nifi-other-graph-services-nar extension installed are vulnerable.


Remediation

Install security update from vendor's website.