CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
Apache NiFi 1.5.0-2.11.0 flow update REST methods lack authorization checks for referenced components, permitting unauthorized Process Group flow replacement (CVE-2026-82561).
Apache NiFi 1.5.0 through 2.11.0 expose REST API methods that replace the entire contents of a Process Group with a client-supplied flow definition, including versioned flow update and rebase operations. Framework authorization for these methods was limited to read and write privileges on the target Process Group, without checking components referenced in the flow (CVE-2026-82561). No severity rating was provided in the disclosure; the affected version range is broad.
- Affects Apache NiFi 1.5.0 through 2.11.0 (nifi-web-api)
- Flow replacement and versioned update methods skip component-level authorization
- Authorization limited to read/write privileges on the target Process Group
- Severity field left blank in the official disclosure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82561 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David Handermann on Sep 16 Severity: Affected versions: - Apache NiFi (org.apache.nifi:nifi-web-api) 1.5.0 through 2.11.0 Description: Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for these methods was limited to read and write privileges on...
This source does not provide full text. Read it at seclists.org.