CVE-2026-82561
CVE-2026-82561 is a medium-severity vulnerability in Apache Nifi with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-862.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 5.9
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-862
- Affected product: Apache Nifi
- Published:
- Last modified:
Description
Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for these methods was limited to read and write privileges on the Process Group itself, unlike the corresponding asynchronous update request methods, which also authorize the components encapsulated in the Process Group along with referenced Controller Services, Parameter Contexts, and Parameter Providers. As a result of the missing authorization, an authenticated user with write access to a Process Group could supply a flow definition that modifies or removes components in descendant Process Groups protected by more restrictive access policies, and could bind components to Controller Services and Parameter Contexts without authorization for those referenced components. Existing verification checks limited the impact to stopped components, and the issue applies only to deployments that use component-level authorization policies, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which applies consistent reference resolution and component authorization across Process Group replacement and versioned flow update methods
Frequently asked questions
- What is CVE-2026-82561?
- Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for these methods was limited to read and write privileges on the Process Group itself, unlike the corresponding asynchronous update request methods, which also authorize the components encapsulated in the Process Group along with referenced Controller Services, Parameter Contexts, and Parameter Providers. As a result of the missing authorization, an authenticated user with write access to a Process Group could supply a flow definition that modifies or removes components in descendant Process Groups protected by more restrictive access policies, and could bind components to Controller Services and Parameter Contexts without authorization for those referenced components. Existing verification checks limited the impact to stopped components, and the issue applies only to deployments that use component-level authorization policies, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which applies consistent reference resolution and component authorization across Process Group replacement and versioned flow update methods
- How severe is CVE-2026-82561?
- CVE-2026-82561 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-82561 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-82561?
- CVE-2026-82561 affects Apache Nifi. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-82561?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-82561 published?
- CVE-2026-82561 was published on 2026-09-16 and last updated on 2026-09-21.
References
- https://lists.apache.org/thread/opk7l8wqvnl85qxlzj3dnxp6qbk27lwm
- http://www.openwall.com/lists/oss-security/2026/09/16/9
Affected products (1)
- cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Nifi
- CVE-2026-68979 — Critical (CVSS 9.8): Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce…
- CVE-2018-1309 — Critical (CVSS 9.8): Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure…
- CVE-2017-15697 — Critical (CVSS 9.8): A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause…
- CVE-2017-5636 — Critical (CVSS 9.8): In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain…
- CVE-2026-68980 — Critical (CVSS 9.1): Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts…
- CVE-2026-39816 — High (CVSS 8.8): The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code…
All CVEs affecting Apache Nifi →
Other CWE-862 (Missing Authorization) vulnerabilities
- CVE-2026-101000 — Critical (CVSS 10.0): A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file…
- CVE-2026-97360 — Critical (CVSS 10.0): HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows…
- CVE-2026-65381 — Critical (CVSS 10.0): A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the…
- CVE-2026-81648 — Critical (CVSS 10.0): The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX…
- CVE-2026-77770 — Critical (CVSS 10.0): The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a…
- CVE-2026-65667 — Critical (CVSS 10.0): Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Browse all CWE-862 (Missing Authorization) vulnerabilities →