Medium severity6.3NVD Advisory· Published Jun 22, 2026· Updated Jun 23, 2026
CVE-2026-44911
CVE-2026-44911
Description
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.nifi:nifi-web-apiMaven | >= 1.15.0, < 2.10.0 | 2.10.0 |
Affected products
4Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2026/06/20/4nvdThird Party AdvisoryMailing ListWEB
- github.com/advisories/GHSA-qvj8-gwpm-4x49ghsaADVISORY
- lists.apache.org/thread/wrj3t4k2bwd2cztyp078f5kj3722qfzynvdVendor AdvisoryMailing ListWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44911ghsaADVISORY
- github.com/apache/nifi/commit/f30f877fb3e0e2a0db7850be8b6d586203860a45ghsaWEB
News mentions
1- Apache NiFi: Three CVEs Disclosed Together — Auth Bypass, SQLi, and Host-Header InjectionVypr Intelligence · Jun 22, 2026