PT-2026-51283 · Apache · Apache Nifi

·

CVE-2026-44913

·

Published

2026-06-22

·

Updated

2026-06-24

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.2.0 through 2.9.0
Description Improper escaping of database table names in the CaptureChangeMySQL Processor allows for the injection of SQL commands through crafted naming. This issue affects installations utilizing the CaptureChangeMySQL Processor.
Recommendations Update to version 2.10.0. As a temporary mitigation, restrict or disable the use of the CaptureChangeMySQL Processor.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2026-44913
CVE-2026-44913

Affected Products

Apache Nifi