https://seclists.org/oss-sec/2026/q3/807: CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration
Published Sep 16, 2026
·Updated
Affected Software
1 affected component
Apache nifi=2.11.0
Frequently Asked Questions
1
What access would an attacker need to exploit the unauthorized enumeration or migration paths?
The attacker must be authenticated and have access to a target Connector. Read access to the Connector permits enumeration of version-controlled Process Group identifiers, names, and flow registry details; write access to the Connector permits migration of a Process Group without write access to that Process Group.
2
What conditions limit the impact of an unauthorized migration?
The source Process Group must be stopped and have empty queues before migration can occur. Migration excludes sensitive property values, although it copies the flow definition, referenced assets, and component state into the Connector and leaves the source Process Group disabled and renamed.