ZeroHour

CVE-2026-81866

CVSS
EPSS
Published
Modified

In the news

CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration

Apache NiFi 2.9.0-2.11.0 Connector configuration update and verification APIs skip authorization for referenced Assets and Secrets (CVE-2026-81866, Low).

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checks on Assets and Secrets referenced in the proposed configuration. Updating or verifying a Connector configuration can apply Asset and Secret references without the caller holding the required privileges. The issue, CVE-2026-81866, is rated Low severity and affects the nifi-web-api component.