As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
Apache NiFi versions 1.5.0 through 2.11.0 contain a missing authorization flaw in REST application programming interface (API) methods that replace Process Group flow definitions. The framework authorization checks were limited to read and write privileges, failing to fully validate access rights for components referenced in flow updates and rebase operations.
Why it matters: Organizations running affected NiFi versions risk unauthorized users modifying data flow configurations, potentially leading to data exfiltration or pipeline manipulation without proper access controls.
- Source published
- First seen by Cybersecurity Tracker