ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 3 sources: “Apache NiFi: Three missing-authorization flaws in REST APIs disclosed same day (CVE-2026-81866, CVE-2026-82561, CVE-2026-86089)” — merged summary and timeline →

CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration

AI summary · glm-5.3-flash

Apache NiFi 2.11.0 Connector Migration REST APIs authorize only against the target Connector, skipping Process Group access checks (CVE-2026-86089, Low).

Apache NiFi 2.11.0 supports migrating version-controlled Process Group contents into a Connector via REST API methods that list eligible migration sources and submit migration requests. Both methods were authorized only against the target Connector, without evaluating user access to the involved Process Groups. The flaw, tracked as CVE-2026-86089, is rated Low severity and affects the nifi-web-api component.

  • Affects only Apache NiFi 2.11.0 (nifi-web-api)
  • Authorization checks omitted for Process Groups used in Connector migration
  • Rated Low severity in the official Apache disclosure
  • Disclosed via the oss-security mailing list by David Handermann

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-86089

NVD description · AI analysis pending
Full article

Posted by David Handermann on Sep 16 Severity: Low Affected versions: - Apache NiFi (org.apache.nifi:nifi-web-api) 2.11.0 Description: Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups involved. The absence of...

This source does not provide full text. Read it at seclists.org.