CVE-2026-44913 Details
Description
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.
A vulnerability exists in the CaptureChangeMySQL Processor of Apache NiFi versions 1.2.0 through 2.9.0, due to improper escaping of database table names. This flaw allows for the injection of SQL commands through crafted table names. Although manual quoted boundaries introduced in Apache NiFi 1.8.0 reduced the risk of injection, they did not address all potential exploitation methods. The vulnerability is only present in Apache NiFi installations that utilize the CaptureChangeMySQL Processor.
Users are advised to upgrade to Apache NiFi version 2.10.0, which includes improved escaping of identifiers to mitigate this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/20/5 | CVE | Third Party AdvisoryMailing List |
| https://lists.apache.org/thread/c8vkt5rz4dqql6sjxgrr3zdkbt1sfmsl | [email protected] | Vendor AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache nifi | >= 1.2.0, < 2.10.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | CVE Modified | CVE |
| Jun 22, 2026 | New CVE Received | [email protected] |