PT-2026-93932 · Apache · Apache Nifi

·

CVE-2026-86089

·

Published

2026-09-16

·

Updated

2026-09-22

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi version 2.11.0
Description An authorization flaw exists in the REST API methods used to list migration sources and submit migration requests when moving version-controlled Process Group contents into a Connector. The system only verified permissions for the target Connector, failing to evaluate access rights for the involved Process Groups. This allows an authenticated user with read access to a Connector to enumerate identifiers, names, and flow registry details of Process Groups they are not authorized to read. Additionally, a user with write access to a Connector can migrate a Process Group they do not have write access to, which copies the flow definition, referenced assets, and component state into the Connector while disabling and renaming the source Process Group. This issue does not affect installations that do not use component-level authorization policies for Process Groups. The migration process requires the source Process Group to be stopped with empty queues and does not include sensitive property values.
Recommendations Upgrade to version 2.12.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2026-86089
CVE-2026-86089

Affected Products

Apache Nifi