CVE-2026-81866 Overview
CVE-2026-81866 is a missing authorization vulnerability [CWE-862] in Apache NiFi versions 2.9.0 through 2.11.0. The flaw affects Connector configuration update and verification REST API methods. These endpoints fail to enforce authorization checks on Assets and Secrets referenced in proposed configurations. The framework only verifies write privileges on the Connector itself, not on referenced Parameter Providers or Assets.
An authenticated user with permission to modify a Connector can apply Secret values backed by a Parameter Provider they are not authorized to read. The same endpoints accept Asset identifiers without verifying Asset ownership by the target Connector.
Critical Impact
Authenticated users authorized to modify a Connector can reference Secrets from Parameter Providers they cannot read, and can attach Assets belonging to other Connectors, breaking authorization boundaries in multi-tenant NiFi deployments.
Affected Products
- Apache NiFi 2.9.0
- Apache NiFi 2.10.0
- Apache NiFi 2.11.0
Discovery Timeline
- 2026-09-16 - CVE-2026-81866 published to NVD
- 2026-09-17 - Last updated in NVD database
Technical Details for CVE-2026-81866
Vulnerability Analysis
Apache NiFi exposes REST API methods that update and verify Connector configurations. These methods accept references to Assets and Secrets as part of the submitted configuration payload. The framework treats write access on the Connector as the sole security boundary for the entire operation.
This design omits authorization checks on the referenced resources. A user with Connector write access can specify Secret references backed by a Parameter Provider they cannot read. NiFi will resolve those Secret values and apply them to the Connector configuration. The same methods accept Asset identifiers without confirming the Asset belongs to the Connector being configured.
Installations that grant uniform authorization across Connectors and Parameter Providers are not exposed, because the Connector write permission functions as the intended boundary. Deployments with differentiated permission models across resource types are affected.
Root Cause
The root cause is missing authorization enforcement on referenced resources during Connector configuration processing. The framework checks the caller's write permission on the Connector but does not check read permission on referenced Parameter Providers or verify Asset ownership. This matches the [CWE-862] Missing Authorization pattern.
Attack Vector
Exploitation requires an authenticated user with write privileges on a target Connector and network access to the NiFi REST API. The attacker submits a configuration update or verification request containing Secret references tied to an unauthorized Parameter Provider, or Asset identifiers belonging to other Connectors. The framework applies those references without further authorization checks. No user interaction is required beyond the attacker's own API call.
No public exploit code is available for this vulnerability. Refer to the Apache Mailing List Thread and the Openwall OSS Security Update for the vendor's technical description.
Detection Methods for CVE-2026-81866
Indicators of Compromise
- REST API calls to Connector configuration update or verification endpoints that include Parameter Provider Secret references from providers the calling user cannot read.
- Connector configurations that reference Asset identifiers owned by unrelated Connectors.
- Audit log entries showing Connector configuration changes by users lacking read access to the referenced Parameter Providers.
Detection Strategies
- Review NiFi audit logs for Connector configuration updates and correlate the caller's identity against the read ACLs of any referenced Parameter Providers.
- Alert on Connector configurations that reference Assets whose parent Connector differs from the modified Connector.
- Baseline Parameter Provider access patterns and flag configuration events that resolve Secrets outside the caller's normal authorization scope.
Monitoring Recommendations
- Enable and forward Apache NiFi provenance and user audit events to a centralized log platform for correlation with identity data.
- Monitor administrative REST API endpoints under /nifi-api/connectors and related configuration paths for anomalous update or verification requests.
- Track changes to Parameter Provider references over time to detect unauthorized reuse of Secret values across Connectors.
How to Mitigate CVE-2026-81866
Immediate Actions Required
- Upgrade Apache NiFi to version 2.12.0, which enforces read authorization on referenced Parameter Providers and validates Asset ownership during Connector configuration update and verification.
- Inventory NiFi deployments running versions 2.9.0 through 2.11.0 and prioritize instances with differentiated permission models across Connectors and Parameter Providers.
- Review existing Connector configurations for Secret and Asset references that may have been applied by users lacking the appropriate authorization.
Patch Information
Apache NiFi 2.12.0 is the vendor-recommended fix. The release adds read authorization checks on referenced Parameter Providers and verifies that referenced Assets belong to the Connector being configured. See the Apache Mailing List Thread for the official advisory.
Workarounds
- Align authorization policies so that users with Connector write access also hold read access to any Parameter Providers they can reference, removing the differentiated privilege condition required for exploitation.
- Restrict Connector modification privileges to trusted administrators until the upgrade to 2.12.0 is completed.
- Rotate Secrets managed by Parameter Providers if audit review indicates unauthorized reference by users lacking read permission.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.