CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7541

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration

Apache NiFi versions 2.9.0 through 2.11.0 fail to enforce authorization checks on Assets and Secrets referenced in Connector configuration updates and verification through REST application programming interface (API) methods. An attacker with access to update or verify Connector configurations could potentially apply Asset and Secret references without proper authorization controls.

Why it matters: Administrators managing Apache NiFi deployments must patch affected versions to prevent unauthorized access to sensitive Assets and Secrets through the API, particularly in multi-tenant or role-based access control environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary