CVE-2026-44911: fallo de gravedad baja en Apache NiFi
Apache NiFi: Incorrect Authorization for Configuration Verification Requests
Publicada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 2.3epss 0.5%
probabilidad de explotación
0.5%top 58% de las CVE
explotación observada
noninguna fuente lo reporta
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/AU:Y/R:U/V:C/RE:L/U:Amber
Productos afectados
Apache Software Foundation · Apache NiFiCVEs relacionadas — Apache NiFi
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-34468HIGHApache NiFi: Potential Code Injection with Database Services using H2EPSS 61.9%CVE-2024-37389MEDIUMApache NiFi: Improper Neutralization of Input in Parameter Context DescriptionEPSS 24.0%CVE-2017-15697—CVE-2017-15697EPSS 4.8%CVE-2018-1309—CVE-2018-1309EPSS 4.5%CVE-2020-1928—CVE-2020-1928EPSS 4.0%CVE-2022-33140—Improper Neutralization of Command Elements in Shell User Group ProviderEPSS 3.7%