Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86089— Apache NiFi: Missing Process Group Authorization for Connector Migration

Quick assessment

Affected
Apache Software Foundation Apache NiFi
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connec

CVSS 2.3 · Low

Affected Version Matrix 1

VendorProduct Version RangeStatus
Apache Software Foundation Apache NiFi 2.11.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86089

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache NiFi: Missing Process Group Authorization for Connector Migration
Source: CVE Program / CVE List V5
Vulnerability Description
Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups involved. The absence of Process Group authorization allowed an authenticated user with read access to a Connector to enumerate the identifiers, names, and flow registry details of version-controlled Process Groups outside the scope of granted read policies. It also allowed a user with write access to a Connector to migrate a Process Group without write access to that Process Group, copying the flow definition, referenced assets, and component state into the Connector, and leaving the source Process Group disabled and renamed. Migration excludes sensitive property values and requires the source Process Group to be stopped with empty queues, which limits the scope of exposure. Apache NiFi installations that do not implement component-level authorization policies for Process Groups are not subject to this vulnerability, because the framework enforces Connector write permissions as the security boundary. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which filters migration sources to Process Groups the requesting user is authorized to read, and requires write access to the source Process Group when submitting a migration request.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/S:P/AU:Y/R:U/V:C/RE:L/U:Clear
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache NiFi 2.11.0 -

II. Public POCs for CVE-2026-86089

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86089

登录查看更多情报信息。

Mailing List Discussions for CVE-2026-86089 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-16 · 20 CVEs total

CVE-2026-87976 7.2 HIGH Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles
CVE-2026-82561 5.9 MEDIUM Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
CVE-2026-81866 0.5 LOW Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configur
CVE-2026-86465 Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via us
CVE-2026-70469 Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests
CVE-2026-82311 Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _us
CVE-2026-86462 Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed
CVE-2026-86792 Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Sched
CVE-2026-82310 Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API
CVE-2026-76186 Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session iden
CVE-2026-76187 Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session J
CVE-2026-86466 Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validate
CVE-2026-59739 Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
CVE-2026-59969 Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
CVE-2026-79993 Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion
CVE-2026-84439 Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
CVE-2026-84501 Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationP
CVE-2026-68536 Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
CVE-2026-76646 Apache MyFaces: Denial of Service via Unbounded Request Parsing

IV. Related Vulnerabilities

V. Comments for CVE-2026-86089

No comments yet


Leave a comment