PT-2026-8394 · Apache · Apache Nifi

David Handermann

·

Published

2026-02-06

·

Updated

2026-02-20

·

CVE-2026-25903

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.1.0 through 2.7.2
Description Apache NiFi installations are affected by a missing authorization check when updating configuration properties on extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges needed to add a component to the flow configuration, but the framework did not verify the restricted status during updates to previously added components. This allows a user with lower privileges to modify the configuration of restricted components, potentially compromising dataflow logic or triggering unsafe actions. Installations that do not implement different authorization levels for Restricted components are not affected, as the framework relies on write permissions as a security boundary.
Recommendations Upgrade to Apache NiFi version 2.8.0 to address this issue.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-02444
BIT-NIFI-2026-25903
CVE-2026-25903
GHSA-C5W7-M8WF-XC77

Affected Products

Apache Nifi