Apache · Apache Nifi · CVE-2026-86089
**Name of the Vulnerable Software and Affected Versions**
Apache NiFi version 2.11.0
**Description**
An authorization flaw exists in the REST API methods used to list migration sources and submit migration requests when moving version-controlled Process Group contents into a Connector. The system only verified permissions for the target Connector, failing to evaluate access rights for the involved Process Groups. This allows an authenticated user with read access to a Connector to enumerate identifiers, names, and flow registry details of Process Groups they are not authorized to read. Additionally, a user with write access to a Connector can migrate a Process Group they do not have write access to, which copies the flow definition, referenced assets, and component state into the Connector while disabling and renaming the source Process Group. This issue does not affect installations that do not use component-level authorization policies for Process Groups. The migration process requires the source Process Group to be stopped with empty queues and does not include sensitive property values.
**Recommendations**
Upgrade to version 2.12.0.