THREATOPS
THREAT OPSThreat News › CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles

CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles

medoss_secPublished 2026-09-16

<p>Posted by David Handermann on Sep 16</p>Severity: High <br /> <br /> Affected versions:<br /> <br /> - Apache NiFi Registry (org.apache.nifi.registry:nifi-registry-framework) 0.4.0 through 2.11.0<br /> <br /> Description:<br /> <br /> Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using <br /> group, artifact, and version coordin

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/808