Vulnerability Description
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | >= 1.12.0, < 2.10.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/ydr34t03xd1n0t9oogpzogjrd5y93838Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/06/20/6Mailing ListThird Party Advisory
FAQ
What is CVE-2026-44914?
CVE-2026-44914 is a vulnerability with a CVSS score of 7.2 (HIGH). Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Re...
How severe is CVE-2026-44914?
CVE-2026-44914 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44914?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Nifi.