ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 3 sources: “Apache NiFi: Three missing-authorization flaws in REST APIs disclosed same day (CVE-2026-81866, CVE-2026-82561, CVE-2026-86089)” — merged summary and timeline →

CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods

mediumVulnerabilityimportance 38CVE-2026-82561
AI summary · glm-5.3-flash

Apache NiFi 1.5.0-2.11.0 flow update REST methods lack authorization checks for referenced components, permitting unauthorized Process Group flow replacement (CVE-2026-82561).

Apache NiFi 1.5.0 through 2.11.0 expose REST API methods that replace the entire contents of a Process Group with a client-supplied flow definition, including versioned flow update and rebase operations. Framework authorization for these methods was limited to read and write privileges on the target Process Group, without checking components referenced in the flow (CVE-2026-82561). No severity rating was provided in the disclosure; the affected version range is broad.

  • Affects Apache NiFi 1.5.0 through 2.11.0 (nifi-web-api)
  • Flow replacement and versioned update methods skip component-level authorization
  • Authorization limited to read/write privileges on the target Process Group
  • Severity field left blank in the official disclosure

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82561

NVD description · AI analysis pending
Full article

Posted by David Handermann on Sep 16 Severity: Affected versions: - Apache NiFi (org.apache.nifi:nifi-web-api) 1.5.0 through 2.11.0 Description: Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for these methods was limited to read and write privileges on...

This source does not provide full text. Read it at seclists.org.