CVE-2026-25903Disclosure(apache / nifi)

MEDIUMCVSS 6.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache nifi systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the annotated component to the flow configuration, but framework authorization did not check restricted status when updating a component previously added. The missing authorization requires a more privileged user to add a restricted component to the flow configuration, but permits a less privileged user to make property configuration changes. Apache NiFi installations that do not implement different levels of authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.8.0 is the recommended mitigation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 7 mentions (2026-02-17); latest day: 1
  • 13 total mentions across 5 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline13 mentions / 5d
02457Mentions · 2026-02-16: 2Mentions · 2026-02-17: 7Mentions · 2026-02-18: 2Mentions · 2026-02-19: 1Mentions · 2026-02-24: 1PoC Mentioned / Linked · 2026-02-19: 1Exploit Tool / Code · 2026-02-19: 1Patch / Workaround · 2026-02-17: 5Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 6Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-24: 102-1602-1702-1802-1902-24
Signal classification4 categories
Disclosure
538.5%
Patch
538.5%
General
215.4%
Exploit
17.7%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-162
Disclosure1General1
2026-02-177
Disclosure2General1Patch4
2026-02-182
Disclosure1Patch1
2026-02-191
Exploit1
2026-02-241
Disclosure1
Full discourse13 posts
  • Gray Hats@the_yellow_fall
    Patch

    Apache NiFi flaw CVE-2026-25903 allows unauthorized users to modify restricted components. Update to version 2.8.0 immediately to secure data pipelines. #ApacheNiFi #CVE202625903 #DataEngineering #CyberSecurity #InfoSec #BigData #DevOps https://securityonline.info/apache-nifi-flaw-cve-2026-25903-lets-users-bypass-restrictions/

    Post summary

    The tweet warns of Apache NiFi CVE‑2026‑25903, which allows unauthenticated users to alter restricted components, and urges users to upgrade to version 2.8.0 to mitigate the vulnerability.

    01021470
    10.3K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Apache patched a critical vulnerability (CVE-2026-25903, CVSSv3 8.7) in Apache NiFi. Attackers could reconfigure components to exfiltrate data, inject malicious logic, or degrade isolation. #Patch #Patch #Patch

    Post summary

    Apache NiFi vulnerability CVE-2026-25903 has been patched; attackers could previously reconfigure components to exfiltrate data, inject malicious logic, or degrade isolation.

    02010234
    7.2K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-25903: Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates https://www.openwall.com/lists/oss-security/2026/02/16/1

    Post summary

    Apache NiFi CVE-2026-25903 has been disclosed as a missing authorization flaw affecting component updates.

    00020483
    4.4K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache NiFi の脆弱性 CVE-2026-25903 が FIX:認可チェック不備によるシステム・コマンド実行の恐れ https://iototsecnews.jp/2026/02/17/apache-nifi-vulnerability-enables-authorization-bypass/ 脆弱性 CVE-2026-25903 (High) の原因は、Apache NiFi において Restricted と注釈されたコンポーネントの設定更新時に、認可チェックが欠如していた点にあります。本来は、追加時に高い権限を必要とする設計ですが、追加後のプロパティ変更において十分な検証が行われていませんでした。その結果、低権限ユーザーであっても、機微なデータフロー設定や処理ロジックを改変できる状態となり、認可バイパスが成立してしまいます。影響範囲は 1.1.0〜2.7.2 であり、2.8.0 で修正されています。ご利用のチームは、ご注意ください。 #Apache #CVE202625903 #NiFi #Vulnerability

    Post summary

    The article reports a high‑severity authorization bypass in Apache NiFi (CVE‑2026‑25903) that allows low‑privilege users to modify data‑flow settings, and notes that the issue is fixed in version 2.8.0.

    01000152
    485 followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣ CVE-2026-25903: https://seclists.org/oss-sec/2026/q1/166 Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates 2⃣ CVE-2025-13176: https://labs.infoguard.ch/advisories/cve-2025-13176_eset-inspect_edr_local-privilege-escalation LPE in ESET Inspect EDR 3⃣ From BRICKSTORM to GRIMBOLT: https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines 0-Day 4⃣ CVE-2026-0770: https://github.com/affix/CVE-2026-0770-PoC Langflow Remote Code Execution 5⃣ JWT Authentication Bypass in OpenID Connect Authenticator for Tomcat https://insinuator.net/2026/02/jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/ 6⃣ CVE-2026-2329: https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/ Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones

    Post summary

    The post catalogs multiple CVEs with accompanying PoC links and exploit references, providing technical details of each vulnerability but no evidence of active exploitation or patch advisories.

    10000217
    3.0K followersView on X
  • キタきつね@foxbook
    Disclosure

    Apache NiFiの脆弱性(CVE-2026-25903)により、ユーザーは制限を回避できる Apache NiFi Flaw (CVE-2026-25903) Lets Users Bypass Restrictions #DailyCyberSecurity (Feb 17) https://securityonline.info/apache-nifi-flaw-cve-2026-25903-lets-users-bypass-restrictions/

    Post summary

    The text announces the Apache NiFi CVE-2026-25903 vulnerability that allows users to bypass restrictions, linking to a blog article for further information.

    00010241
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25903 Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based… https://www.cve.org/CVERecord?id=CVE-2026-25903

    Post summary

    The advisory announces CVE-2026-25903, an authorization bypass in Apache NiFi versions 1.1.0 through 2.7.2, with no PoC, exploit, patch or evidence of active exploitation indicated.

    00010447
    56.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25903 CVE-2026-25903 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25903 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post merely references CVE-2026-25903 and provides links to vulnerability details and alert customization, without any technical, exploit, or mitigation information.

    0001043
    4.0K followersView on X
  • eSecurityPlanet@eSecurityPlanet
    General

    CVE-2026-25903 Impacts Apache NiFi Users https://bit.ly/3Om6A5V

    Post summary

    The post only references CVE-2026-25903 impacting Apache NiFi users and includes a link, but offers no details on exploitation, patches, or technical specifics.

    0000071
    6.9K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Apache NiFi High-Severity AuthZ Bypass Lets Low-Priv Users Tamper With “Restricted” Components (CVE-2026-25903) A missing authorization check lets authenticated, lower-privileged NiFi users modify properties on already-added “Restricted” extension components, bypassing the extra controls meant to guard high-risk processors (OS command/script execution, sensitive integrations). Upgrade to NiFi 2.8.0 to fix and review RBAC separation for restricted components to prevent privilege escalation in tiered-access environments. 🎯 Target: Global/Apache NiFi Deployments #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/critical-apache-nifi-vulnerabilities-enable-authorization-bypass/

    Post summary

    The tweet announces a high‑severity authorization bypass (CVE‑2026‑25903) in Apache NiFi that allows low‑privileged users to tamper with restricted components, and recommends upgrading to NiFi 2.8.0 to mitigate the flaw.

    0000053
    176 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity: Apache NiFi 1.1.0 – 2.7.2 has a missing authorization flaw, risking unauthorized config changes by lower-priv users. Upgrade to 2.8.0 now! 🔒 Details: https://radar.offseq.com/threat/cve-2026-25903-cwe-862-missing-authorization-in-ap-96d68c81 #OffSeq #NiFi #inf... https://t.co/C6AQo4XmbM

    Post summary

    Apache NiFi versions 1.1.0–2.7.2 have a disclosed missing authorization flaw (CVE‑2026‑25903) that could allow lower‑privileged users to change configuration; users are urged to upgrade to 2.8.0 to resolve the issue.

    0000041
    265 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Apache NiFi discloses high severity auth bypass CVE-2026-25903, allowing low privilege users to modify restricted components in v1.1.0-2.7.2. Users urged to upgrade to 2.8.0. #vulnerability https://threatcluster.io/cluster/apache-nifi-vulnerability-cve-2026-25903-allows-authorizatio-97e1dcf7

    Post summary

    A high‑severity authentication bypass (CVE‑2026‑25903) in Apache NiFi versions 1.1.0–2.7.2 allows low‑privilege users to modify restricted components; users are advised to upgrade to 2.8.0.

    0000053
    71 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Apache NiFi CVE-2026-25903 Lets Low-Priv Users Bypass “Restricted” Controls and Alter Sensitive Flows Apache fixed a high-severity authorization-bypass in NiFi where missing checks allow a lower-privileged user to modify configuration properties of already-added “Restricted” extension components, potentially tampering with sensitive dataflow logic or triggering unsafe actions. Affected versions are 1.1.0–2.7.2; upgrade to 2.8.0+ to restore proper enforcement. 🎯 Target: Global/Apache NiFi Deployments (Dataflow Pipelines) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/apache-nifi-vulnerability/

    Post summary

    Apache NiFi CVE-2026-25903 is an authorization‑bypass that lets low‑privileged users modify restricted components; upgrading to 2.8.0+ resolves the issue.

    0000056
    176 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more