https://seclists.org/oss-sec/2026/q2/988: CVE-2026-44911: Apache NiFi: Incorct Authorization for Configuration Verification quests
Published Jun 20, 2026
·Updated
Affected Software
1 affected component
Apache Apache NiFi>=1.15.0<=2.9.0
Frequently Asked Questions
1
What is the severity of CVE-2026-44911?
CVE-2026-44911 is classified with a moderate severity level due to incorrect authorization handling.
2
How do I fix CVE-2026-44911?
To fix CVE-2026-44911, upgrade Apache NiFi to a version later than 2.9.0 that includes the necessary authorization fixes.
3
Which versions of Apache NiFi are affected by CVE-2026-44911?
CVE-2026-44911 affects Apache NiFi versions from 1.15.0 through 2.9.0.
4
What does CVE-2026-44911 impact in Apache NiFi?
CVE-2026-44911 impacts the authorization handling for component configuration verification requests.
5
Who is at risk from CVE-2026-44911?
Clients with read access in Apache NiFi are at risk from CVE-2026-44911 as they can submit unauthorized configuration properties.