CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7538

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles

Apache NiFi Registry versions 0.4.0 through 2.11.0 contain a path manipulation vulnerability in the default file persistence provider. The flaw allows attackers to exploit improperly validated group, artifact, and version coordinates from uploaded NAR manifests to write files outside intended directories.

Why it matters: Organizations deploying NiFi Registry for extension management face arbitrary file write risk; administrators should prioritize patching to version 2.12.0 or later.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary