SQL injection in Apache Nifi - CVE-2026-44913

 

SQL injection in Apache Nifi - CVE-2026-44913

Published: August 25, 2026


Vulnerability identifier: #VU145261
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44913
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in CaptureChangeMySQL Processor when processing crafted database table names. A remote user can use a specially crafted table name to execute arbitrary SQL commands.

Only Apache NiFi installations using the CaptureChangeMySQL Processor are vulnerable.


Affected software

Apache Nifi

How to mitigate CVE-2026-44913

Install security update from vendor's website.

Apache Nifi - update to 2.10.0

External References

Related Security Bulletins