As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration
Apache NiFi 2.11.0 fails to validate authorization on Process Groups when migrating their contents into Connectors via REST application programming interface (API) methods. An attacker with access to a target Connector could exploit this to migrate Process Group contents without proper permissions. The vulnerability carries low severity.
Why it matters: Organizations running Apache NiFi 2.11.0 should assess whether users with Connector access can reach Process Groups they should not modify, and apply updates or restrict API access to limit exposure.
- Source published
- First seen by Cybersecurity Tracker