Apache NiFi: Three missing-authorization flaws in REST APIs disclosed same day (CVE-2026-81866, CVE-2026-82561, CVE-2026-86089)
Apache NiFi 1.5.0-2.11.0 nifi-web-api REST endpoints skip authorization checks: Assets and Secrets referenced in Connector configuration updates (CVE-2026-81866, Low), components referenced in Process Group flow replacement (CVE-2026-82561, severity unrated),…
Three missing-authorization vulnerabilities in Apache NiFi's nifi-web-api component were disclosed via the oss-security mailing list on 2026-09-16. CVE-2026-81866 (rated Low) affects Apache NiFi 2.9.0 through 2.11.0: Connector configuration update and verification REST API methods do not enforce authorization on Assets and Secrets referenced in the proposed configuration, so updating or verifying a Connector configuration can apply Asset and Secret references without the caller holding the required privileges. CVE-2026-82561 affects a much broader range, Apache NiFi 1.5.0 through 2.11.0: REST API methods that replace the entire contents of a Process Group with a client-supplied flow definition, including versioned flow update and rebase operations, limited authorization to read and write privileges on the target Process Group without checking components referenced in the flow, permitting unauthorized Process Group flow replacement; no severity rating was provided in the disclosure. CVE-2026-86089 (rated Low) affects only Apache NiFi 2.11.0: REST API methods that list eligible migration sources and submit migration requests for moving version-controlled Process Group contents into a Connector were authorized only against the target Connector, without evaluating user access to the involved Process Groups. All three issues are in the nifi-web-api component and affect versions through 2.11.0; the disclosures state affected version ranges but do not mention patched releases.
- CVE-2026-81866 (Low): Apache NiFi 2.9.0 through 2.11.0 Connector configuration update and verification REST APIs skip authorization for referenced Assets and Secrets (nifi-web-api).
- CVE-2026-82561 (severity field left blank in the official disclosure): Apache NiFi 1.5.0 through 2.11.0 flow replacement and versioned flow update/rebase REST methods authorize only read/write privileges on the target Process Group,…
- CVE-2026-86089 (Low): Apache NiFi 2.11.0 Connector Migration REST APIs (listing eligible migration sources and submitting migration requests) authorize only against the target Connector and omit Process Group access checks (nifi-web-api).
- All three vulnerabilities are in the nifi-web-api component and affect versions through 2.11.0; the broadest affected range is 1.5.0-2.11.0 (CVE-2026-82561).
- All three disclosures were published via the oss-security mailing list on 2026-09-16; the Connector Migration disclosure was made by David Handermann.
- Sources agree on scope and component but disagree on severity disclosure: two issues carry a Low rating in the official Apache disclosures, while CVE-2026-82561 has no severity rating.
Coverage timelineoldest first · each row is one article
- · 2h agoCVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
oss-security· 24
Apache NiFi 2.9.0-2.11.0 Connector configuration update and verification APIs skip authorization for referenced Assets and Secrets (CVE-2026-81866, Low).
- · 2h agoCVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
oss-security· 38
Apache NiFi 1.5.0-2.11.0 flow update REST methods lack authorization checks for referenced components, permitting unauthorized Process Group flow replacement (CVE-2026-82561).
- · 2h agoCVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration
oss-security· 24
Apache NiFi 2.11.0 Connector Migration REST APIs authorize only against the target Connector, skipping Process Group access checks (CVE-2026-86089, Low).
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81866 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-82561 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-86089 | NVD description · AI analysis pending | — | — | — | — | — |