Improper access control in Apache Nifi - CVE-2026-44911

 

Improper access control in Apache Nifi - CVE-2026-44911

Published: August 25, 2026


Vulnerability identifier: #VU145260
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44911
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to invoke configuration verification methods with alternative settings.

The vulnerability exists due to improper access control in component configuration verification requests when submitting proposed configuration properties. A remote user can submit crafted configuration properties to invoke configuration verification methods with alternative settings.

Only installations that implement different authorization levels for viewing and modifying component configuration are vulnerable.


Affected software

Apache Nifi

How to mitigate CVE-2026-44911

Install security update from vendor's website.

Apache Nifi - update to 2.10.0

External References

Related Security Bulletins