CVE-2026-87976
Last modified
CVE-2026-87976 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | >= 0.4.0, < 2.12.0 |
References
- https://lists.apache.org/thread/kw89toml5zq20ry3279mx7y184vrlb8xMailing List, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2026/09/16/11Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-87976?
How severe is CVE-2026-87976?
How do I fix CVE-2026-87976?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-87961ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-b…7.1
- CVE-2026-87962t-digest versions 3.1 through 3.3 contain a denial of servic…7.5
- CVE-2026-87963The Yo WordPress plugin from 1.1 through 1.3.1 does not sani…8.6
- CVE-2026-87965The Easy Appointments WordPress plugin before 4.0.2.2 does n…4.8
- CVE-2026-87966The Easy Appointments WordPress plugin before 4.0.2.2 does n…5.3
- CVE-2026-8797An access control deficiency vulnerability exists in Express…8.5
- CVE-2026-87978The Paymob for WooCommerce WordPress plugin before 4.1.14 do…5.3
- CVE-2026-87979The Paymob for WooCommerce WordPress plugin before 4.1.14 do…5.3
- CVE-2026-8798In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3…8.7
- CVE-2026-87981The Paymob for WooCommerce WordPress plugin before 4.1.14 do…4.7
- CVE-2026-87983An arbitrary file read vulnerability in Mistral Vibe, introd…9.2
- CVE-2026-87984An arbitrary file write vulnerability in Mistral Vibe, intro…9.3
Are you affected by CVE-2026-87976?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
