CVE-2026-44914Patch(apache / nifi)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache nifi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-23); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-20: 1Mentions · 2026-06-22: 1Mentions · 2026-06-23: 2Mentions · 2026-08-04: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-06-23: 2Patch / Workaround · 2026-08-04: 1Technical Details · 2026-06-22: 1Technical Details · 2026-06-23: 2Technical Details · 2026-08-04: 106-2006-2206-2308-04
Signal classification2 categories
Patch
480.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-201
General1
2026-06-221
Patch1
2026-06-232
Patch2
2026-08-041
Patch1
Full discourse5 posts
  • Checkmarx Zero@CheckmarxZero
    Patch

    🚨 CVE-2026-44914 (High) affects Apache NiFi versions 1.12.0 through 2.9.0. The vulnerability stems from missing authorization enforcement that allows users with general write access to add Restricted components when replacing Process Groups, bypassing the elevated permissions normally required, and enabling actions beyond intended privileges. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, as it removes the framework’s implementation of Restricted status authorization. More details: https://devhub.checkmarx.com/cve-details/CVE-2026-44914/

    Post summary

    The post discloses CVE-2026-44914 as a high‑risk access‑control flaw in Apache NiFi, verifies technical details, and recommends upgrading to 2.9.0 as a patch.

    0002099
    242 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Apache NiFi users, be aware: vulnerabilities like CVE-2026-44913 and CVE-2026-44914 in versions 1.2.0 through 2.9.0 could expose your systems to SQL injection and authorization bypass risks. Upgrading to the latest versions is crucial to safeguard your data integration processes. #ApacheNiFi #CyberSecurity #DataIntegration #SQLInjection #AuthorizationBypass #SoftwareUpdate https://thedailytechfeed.com/apache-nifi-vulnerabilities-expose-systems-to-security-risks/

    Post summary

    The post alerts users to CVE-2026-44913 and CVE-2026-44914 in Apache NiFi that allow SQL injection and auth bypass, and urges them to upgrade to the latest version to mitigate the risk.

    0000059
    603 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Recent CVEs impact Apache NiFi (CVE-2026-54665, CVE-2026-44914) & critical DNS metadata leakage noted in QUIC/TLS (June 22). This exposes data privacy in transit. Patch & secure now! #Cybersecurity #Vulnerabilities #DataPrivacy

    Post summary

    The tweet highlights newly disclosed CVEs affecting Apache NiFi and DNS metadata leakage in QUIC/TLS, emphasizing the need for users to apply patches to protect data privacy during transit.

    0000048
    14 followersView on X
  • Can Artuc@canartuc
    Patch

    Apache NiFi 2.10.0 landed June 20 fixing four flaws, led by CVE-2026-44914: a user with general write access could add components that need Restricted-annotation permissions, bypassing the check. It affects 1.12.0 through 2.9.0. How do you scope write access in your NiFi flows?

    Post summary

    Apache NiFi 2.10.0 was released on June 20 to fix four vulnerabilities, including CVE‑2026‑44914, which allowed users with general write access to add restricted components by bypassing permission checks. The update provides the necessary patch to resolve the issue.

    0000035
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44914 CVE-2026-44914 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44914

    Post summary

    The content merely lists the CVE number and links to a generic vulnerability page with no additional technical, exploit, or mitigation information.

    0000037
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more