Skip to main content
Vulnerability Database/CVE-2026-86089

CVE-2026-86089: Apache NiFi Auth Bypass Vulnerability

CVE-2026-86089 is an authentication bypass flaw in Apache NiFi 2.11.0 that allows unauthorized users to enumerate and migrate Process Groups without proper authorization. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-86089 Overview

CVE-2026-86089 is a missing authorization vulnerability [CWE-862] in Apache NiFi 2.11.0. The flaw affects REST API methods that migrate version-controlled Process Groups into Connectors. The framework authorizes both methods against the target Connector alone, without evaluating access to the Process Groups involved. An authenticated user with read access to a Connector can enumerate identifiers, names, and flow registry details of Process Groups outside their granted read policies. A user with write access to a Connector can migrate a Process Group without holding write access to that Process Group.

Critical Impact

Authenticated users can enumerate metadata and copy flow definitions of version-controlled Process Groups outside their granted read and write policies.

Affected Products

  • Apache NiFi 2.11.0
  • Apache NiFi installations that implement component-level authorization policies for Process Groups
  • Fixed in Apache NiFi 2.12.0

Discovery Timeline

  • 2026-09-16 - CVE-2026-86089 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-86089

Vulnerability Analysis

Apache NiFi 2.11.0 exposes REST API methods that list eligible migration sources and submit migration requests for moving version-controlled Process Groups into a Connector. The framework enforces authorization only on the target Connector. It does not evaluate the caller's access to the Process Groups referenced during migration.

The listing endpoint returns identifiers, names, and flow registry details for version-controlled Process Groups that fall outside the requester's read policies. The migration endpoint copies the flow definition, referenced assets, and component state into the Connector. After migration, the source Process Group is left disabled and renamed. Migration excludes sensitive property values and requires the source Process Group to be stopped with empty queues, which limits data exposure to flow structure and non-sensitive configuration.

Root Cause

The vulnerability stems from a missing authorization check [CWE-862]. The framework treats Connector write permission as the sole security boundary for migration operations. It does not enforce component-level authorization on the source Process Group, its assets, or its flow registry metadata.

Attack Vector

An attacker requires authenticated network access and at least read or write policy on a target Connector. With read access, the attacker enumerates Process Group metadata across the instance. With write access, the attacker submits a migration request against a Process Group they otherwise cannot modify, obtaining a copy of the flow inside the Connector they control. Installations that do not configure component-level authorization policies for Process Groups are not affected, because the framework consistently enforces Connector write permissions in that deployment model.

No verified proof-of-concept code is available. See the Apache Mailing List Thread for advisory details.

Detection Methods for CVE-2026-86089

Indicators of Compromise

  • Unexpected Process Groups appearing inside Connectors, particularly with copied flow definitions and referenced assets.
  • Source Process Groups that are unexpectedly stopped, disabled, and renamed after migration completes.
  • REST API activity from low-privileged accounts against migration source listing and migration submission endpoints.

Detection Strategies

  • Audit NiFi REST API access logs for calls to Process Group migration endpoints originating from accounts without corresponding Process Group write policies.
  • Correlate Connector modification events with the identity of the requesting user and the source Process Group owner.
  • Review NiFi flow change history for Process Group rename and disable events that align with migration requests.

Monitoring Recommendations

  • Enable and centrally ingest NiFi user action provenance and REST audit logs.
  • Alert on enumeration patterns where a single account queries migration source listings across multiple Connectors in a short interval.
  • Monitor for creation of Connectors that receive flow definitions from Process Groups outside the requester's authorization scope.

How to Mitigate CVE-2026-86089

Immediate Actions Required

  • Upgrade Apache NiFi to version 2.12.0, which filters migration sources to Process Groups the requesting user is authorized to read and requires write access to the source Process Group when submitting a migration request.
  • Review existing Connector write policies and reduce assignments to the minimum set of trusted users.
  • Audit recent migration activity to identify unauthorized flow copies created before the upgrade.

Patch Information

Apache NiFi 2.12.0 is the fixed release. The patch adds authorization checks so the migration source listing filters Process Groups by the caller's read policy, and the migration submission endpoint requires write access to the source Process Group. Refer to the OpenWall OSS Security Update for the maintainer announcement.

Workarounds

  • Remove component-level authorization policies for Process Groups if operationally acceptable, since the framework enforces Connector write permissions as the security boundary in that configuration.
  • Restrict Connector write policies to administrative users until the upgrade is applied.
  • Block or gate access to Process Group migration REST endpoints at a reverse proxy for non-administrative users.
bash
# Verify NiFi version after upgrade
./bin/nifi.sh --version
# Expected output: Apache NiFi 2.12.0 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.