https://seclists.org/oss-sec/2026/q3/807: CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration

Published Sep 16, 2026
·
Updated

Affected Software

1 affected component
Apache nifi=2.11.0

Frequently Asked Questions

1

What access would an attacker need to exploit the unauthorized enumeration or migration paths?

The attacker must be authenticated and have access to a target Connector. Read access to the Connector permits enumeration of version-controlled Process Group identifiers, names, and flow registry details; write access to the Connector permits migration of a Process Group without write access to that Process Group.

2

What conditions limit the impact of an unauthorized migration?

The source Process Group must be stopped and have empty queues before migration can occur. Migration excludes sensitive property values, although it copies the flow definition, referenced assets, and component state into the Connector and leaves the source Process Group disabled and renamed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203