THREAT OPS › Threat News › CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
<p>Posted by David Handermann on Sep 16</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache NiFi (org.apache.nifi:nifi-web-api) 1.5.0 through 2.11.0<br /> <br /> Description:<br /> <br /> Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a <br /> client-supplied flow definition, covering Process Group flow replacemen
Indicators of compromise
- CVE-2026-82561cve
Original source: https://seclists.org/oss-sec/2026/q3/806