Missing Authorization in Apache Nifi - CVE-2026-44914
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to bypass restricted component authorization.
The vulnerability exists due to improper access control in process group replacement handling in nifi-web-api when replacing process groups that include extension components with restricted status. A remote user can replace a process group containing restricted components to bypass restricted component authorization.
Only installations that implement specific authorization for restricted components are vulnerable.