CVE-2026-44913General(apache / nifi)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache nifi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-20: 1Mentions · 2026-08-04: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-08-04: 106-2008-04
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-201
General1
2026-08-041
Disclosure1
Full discourse2 posts
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Apache NiFi users, be aware: vulnerabilities like CVE-2026-44913 and CVE-2026-44914 in versions 1.2.0 through 2.9.0 could expose your systems to SQL injection and authorization bypass risks. Upgrading to the latest versions is crucial to safeguard your data integration processes. #ApacheNiFi #CyberSecurity #DataIntegration #SQLInjection #AuthorizationBypass #SoftwareUpdate https://thedailytechfeed.com/apache-nifi-vulnerabilities-expose-systems-to-security-risks/

    Post summary

    The post alerts Apache NiFi users to CVE-2026-44913 and CVE-2026-44914, which enable SQL injection and authorization bypass, and recommends updating to the latest versions to mitigate the risks.

    0000059
    603 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44913 CVE-2026-44913 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44913 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post simply lists CVE‑2026‑44913 and links to its page on vulmon.com, offering no additional technical, exploit, or patch information.

    0000042
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more