CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
Apache NiFi 2.9.0-2.11.0 Connector configuration update and verification APIs skip authorization for referenced Assets and Secrets (CVE-2026-81866, Low).
Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checks on Assets and Secrets referenced in the proposed configuration. Updating or verifying a Connector configuration can apply Asset and Secret references without the caller holding the required privileges. The issue, CVE-2026-81866, is rated Low severity and affects the nifi-web-api component.
24