CVE-2026-44914 Details
Description
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.
A vulnerability exists in Apache NiFi versions 1.12.0 through 2.9.0, where the framework fails to enforce authorization for components marked with the Restricted annotation when Process Groups are replaced. The Restricted annotation denotes additional privileges required, but the authorization framework did not verify this status during the replacement process. As a result, users with general write access can introduce components with Restricted status. This vulnerability does not affect Apache NiFi installations that properly implement authorization for Restricted components, as the framework's default security boundary enforces write permissions. The issue is tracked as NIFI-15845.
Upgrading to Apache NiFi version 2.9.0 is recommended, as this version addresses the vulnerability by removing the authorization requirement for Restricted status components.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/20/6 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/ydr34t03xd1n0t9oogpzogjrd5y93838 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache nifi | >= 1.12.0, < 2.10.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | CVE Modified | CVE |
| Jun 22, 2026 | New CVE Received | [email protected] |