Missing Authorization in Apache Nifi - CVE-2026-39816
Published: August 25, 2026 / Updated: September 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in TinkerpopClientService when configuring bytecode submission for the script submission type. A remote user can configure the service to execute Groovy script code to execute arbitrary code.
Only installations that use fine-grained authorization and have the optional nifi-other-graph-services-nar extension installed are vulnerable.