CVE-2026-86089
Last modified
CVE-2026-86089 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups involved. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups involved. The absence of Process Group authorization allowed an authenticated user with read access to a Connector to enumerate the identifiers, names, and flow registry details of version-controlled Process Groups outside the scope of granted read policies. It also allowed a user with write access to a Connector to migrate a Process Group without write access to that Process Group, copying the flow definition, referenced assets, and component state into the Connector, and leaving the source Process Group disabled and renamed. Migration excludes sensitive property values and requires the source Process Group to be stopped with empty queues, which limits the scope of exposure. Apache NiFi installations that do not implement component-level authorization policies for Process Groups are not subject to this vulnerability, because the framework enforces Connector write permissions as the security boundary. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which filters migration sources to Process Groups the requesting user is authorized to read, and requires write access to the source Process Group when submitting a migration request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | 2.11.0 |
References
- https://lists.apache.org/thread/lnpqnn61k62fkgxqd9cftf7sr77jhrk1Mailing List, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2026/09/16/10Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-86089?
How severe is CVE-2026-86089?
How do I fix CVE-2026-86089?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86081n8n is an open source workflow automation platform. Prior to…7.1
- CVE-2026-86082n8n is an open source workflow automation platform. Prior to…6.5
- CVE-2026-86083n8n is an open source workflow automation platform. Prior to…8.8
- CVE-2026-86084n8n is an open source workflow automation platform. Prior to…5.5
- CVE-2026-86085n8n is an open source workflow automation platform. Prior to…4.9
- CVE-2026-86087IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 cou…4.3
- CVE-2026-8609An unauthenticated attacker can repeatedly call Grafana's OA…7.5
- CVE-2026-86090ntopng before 6.7.260717 fails to perform authorization chec…7.1
- CVE-2026-86091ntopng before 6.7.260717 fails to check user privileges in t…7.1
- CVE-2026-86093IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 cou…7.5
- CVE-2026-86095Unidata netcdf-c through 4.10.1 contains an out-of-bounds wr…7.8
- CVE-2026-86096PX4 Autopilot through 1.17.0 contains a use-after-free vulne…5.9
Are you affected by CVE-2026-86089?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
