PT-2026-8394 · Apache · Apache Nifi
David Handermann
·
Published
2026-02-06
·
Updated
2026-02-20
·
CVE-2026-25903
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache NiFi versions 1.1.0 through 2.7.2
Description
Apache NiFi installations are affected by a missing authorization check when updating configuration properties on extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges needed to add a component to the flow configuration, but the framework did not verify the restricted status during updates to previously added components. This allows a user with lower privileges to modify the configuration of restricted components, potentially compromising dataflow logic or triggering unsafe actions. Installations that do not implement different authorization levels for Restricted components are not affected, as the framework relies on write permissions as a security boundary.
Recommendations
Upgrade to Apache NiFi version 2.8.0 to address this issue.
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi