https://seclists.org/oss-sec/2026/q1/166: CVE-2026-25903: Apache NiFi: Missing Authorization of stricted Permissions for Component Updates
Published Feb 16, 2026
·Updated
Affected Software
2 affected components
Apache nifi>=1.1.0<2.8.0
maven/org.apache.nifi/nifi-web-api>=1.1.0<2.8.0
Frequently Asked Questions
1
What is the severity of CVE-2026-25903?
CVE-2026-25903 is classified as a high severity vulnerability due to missing authorization in Apache NiFi.
2
Which versions of Apache NiFi are affected by CVE-2026-25903?
CVE-2026-25903 affects Apache NiFi versions 1.1.0 through 2.7.2.
3
How do I fix CVE-2026-25903?
To fix CVE-2026-25903, upgrade Apache NiFi to version 2.8.0 or later.
4
What are the implications of CVE-2026-25903?
CVE-2026-25903 allows unauthorized users to update configuration properties on extension components, potentially compromising security.
5
What components in Apache NiFi are impacted by CVE-2026-25903?
CVE-2026-25903 impacts extension components that require specific permissions based on restricted annotations.