Improper access control in Apache Nifi - CVE-2026-44911
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to invoke configuration verification methods with alternative settings.
The vulnerability exists due to improper access control in component configuration verification requests when submitting proposed configuration properties. A remote user can submit crafted configuration properties to invoke configuration verification methods with alternative settings.
Only installations that implement different authorization levels for viewing and modifying component configuration are vulnerable.