CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration
Apache NiFi 2.11.0 Connector Migration REST APIs authorize only against the target Connector, skipping Process Group access checks (CVE-2026-86089, Low).
Apache NiFi 2.11.0 supports migrating version-controlled Process Group contents into a Connector via REST API methods that list eligible migration sources and submit migration requests. Both methods were authorized only against the target Connector, without evaluating user access to the involved Process Groups. The flaw, tracked as CVE-2026-86089, is rated Low severity and affects the nifi-web-api component.
- Affects only Apache NiFi 2.11.0 (nifi-web-api)
- Authorization checks omitted for Process Groups used in Connector migration
- Rated Low severity in the official Apache disclosure
- Disclosed via the oss-security mailing list by David Handermann
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86089 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David Handermann on Sep 16 Severity: Low Affected versions: - Apache NiFi (org.apache.nifi:nifi-web-api) 2.11.0 Description: Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups involved. The absence of...
This source does not provide full text. Read it at seclists.org.