https://seclists.org/oss-sec/2026/q3/806: CVE-2026-82561: Apache NiFi: Missing Authorization for Components fenced in Flow Update Methods
Published Sep 16, 2026
·Updated
Affected Software
1 affected component
Apache nifi>=1.5.0<=2.11.0
Frequently Asked Questions
1
Which deployments are meaningfully exposed to this issue?
The issue applies only to deployments that use component-level access policies. Affected deployments must run Apache NiFi nifi-web-api versions 1.5.0 through 2.11.0.
2
What access does an attacker need to exploit it?
An attacker must be authenticated and have write access to the target Process Group. They could then submit a replacement, versioned update, or rebase flow definition affecting protected descendant components or referencing Controller Services and Parameter Contexts without authorization for them.
3
Are running components affected?
Existing verification checks limit the impact to stopped components. The provided information does not indicate that running components can be modified or removed through this issue.