https://seclists.org/oss-sec/2026/q2/990: CVE-2026-44914: Apache NiFi: Missing Authorization of stricted Permissions when placing Flow Contents
Published Jun 20, 2026
·Updated
Affected Software
1 affected component
maven/org.apache.nifi/nifi-web-api>=1.12.0<=2.9.0
Frequently Asked Questions
1
What is the severity of CVE-2026-44914?
CVE-2026-44914 has been classified with a high severity due to unauthorized access risks in Apache NiFi.
2
How do I fix CVE-2026-44914?
To fix CVE-2026-44914, upgrade Apache NiFi to a version later than 2.9.0.
3
Which versions are affected by CVE-2026-44914?
CVE-2026-44914 affects Apache NiFi versions 1.12.0 through 2.9.0.
4
What are the consequences of CVE-2026-44914?
The consequences of CVE-2026-44914 include potential unauthorized manipulation of Process Groups in Apache NiFi.
5
Who is impacted by CVE-2026-44914?
Organizations using Apache NiFi versions 1.12.0 through 2.9.0 are at risk due to CVE-2026-44914.