CVE-2026-39816Disclosure(apache / nifi)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Script execution in the service prior to submitting the query. The missing Restricted annotation allows users without the Execute Code Permission to configure the Service in installations that use fine-grained authorization and have the optional TinkerpopClientService installed. Apache NiFi installations that do not have the nifi-other-graph-services-nar installed are not subject to this vulnerability. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-13); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-13: 2Mentions · 2026-05-08: 1Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-12: 1Technical Details · 2026-04-13: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 104-1305-0805-1105-12
Signal classification3 categories
Disclosure
240.0%
PoC
240.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-132
Disclosure1General1
2026-05-081
Disclosure1
2026-05-111
PoC1
2026-05-121
PoC1
Full discourse5 posts
  • ZeroPath@ZeroPathAI
    PoC

    ZeroPath Research discovered CVE-2026-39816, a high severity vulnerability in Apache NiFi. Prior to version 2.9.0, an oversight in the permission model allowed users without the EXECUTE_CODE permissions to run arbitrary code. For more details and a POC: https://zeropath.com/blog/nifi-cve-2026-39816-privesc-rce https://t.co/qHETioC5HG

    Post summary

    ZeroPath Research discovered CVE-2026-39816 in Apache NiFi and provided a proof‑of‑concept illustrating arbitrary code execution via a permission model flaw.

    02093425
    253 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-39816: Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService https://www.openwall.com/lists/oss-security/2026/04/13/8

    Post summary

    The message announces CVE-2026-39816, noting a missing permission that could allow higher privilege execution, but offers no proof of exploitation, tooling, or fixes.

    00030434
    4.6K followersView on X
  • LeftenantZero@LeftenantZero
    PoC

    CVE-2026-39816: Missing permission annotation leads to post -auth RCE in Apache NiFi. Our blog has the details and a working POC. https://zeropath.com/blog/nifi-cve-2026-39816-privesc-rce

    Post summary

    The post highlights CVE‑2026‑39816, a post‑authentication remote code execution flaw in Apache NiFi, and indicates that a working proof‑of‑concept is available in the linked blog.

    00010113
    270 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39816 The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through… https://www.cve.org/CVERecord?id=CVE-2026-39816

    Post summary

    The text announces a vulnerability where the TinkerpopClientService component in Apache NiFi 2.0.0‑M1 lacks the Restricted annotation, providing technical details but no exploitation or patch information.

    00000124
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39816 CVE-2026-39816 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39816

    Post summary

    The post simply references CVE-2026-39816 and provides a link to a vulnerability details page, without any further information on exploits, patches, or active use.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more