SQL injection in Apache Nifi - CVE-2026-44913
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in CaptureChangeMySQL Processor when processing crafted database table names. A remote user can use a specially crafted table name to execute arbitrary SQL commands.
Only Apache NiFi installations using the CaptureChangeMySQL Processor are vulnerable.