30
30
30
35
CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration
Apache NiFi 2.11.0 Connector Migration REST APIs authorize only against the target Connector, skipping Process Group access checks (CVE-2026-86089, Low).
Apache NiFi 2.11.0 supports migrating version-controlled Process Group contents into a Connector via REST API methods that list eligible migration sources and submit migration requests. Both methods were authorized only against the target Connector, without evaluating user access to the involved Process Groups. The flaw, tracked as CVE-2026-86089, is rated Low severity and affects the nifi-web-api component.
24
30
30
30
30
30
30
30