
🚨 CVE-2026-44914 (High) affects Apache NiFi versions 1.12.0 through 2.9.0. The vulnerability stems from missing authorization enforcement that allows users with general write access to add Restricted components when replacing Process Groups, bypassing the elevated permissions normally required, and enabling actions beyond intended privileges. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, as it removes the framework’s implementation of Restricted status authorization. More details: https://devhub.checkmarx.com/cve-details/CVE-2026-44914/
Post summary
The post discloses CVE-2026-44914 as a high‑risk access‑control flaw in Apache NiFi, verifies technical details, and recommends upgrading to 2.9.0 as a patch.




