Apache NiFi disclosed a high-severity authorization flaw, tracked as CVE-2026-25903, that allows a lower-privileged user to modify configuration properties of Restricted extension components after they have been added to a flow by a more privileged user. The issue affects NiFi versions 1.1.0 through 2.7.2 and stems from missing authorization checks during component property updates: the framework enforced the extra privileges required to add a Restricted component, but did not consistently re-check the component’s restricted status when updating it, enabling an authorization bypass (CWE-862). Potential impact includes tampering with dataflow logic and, depending on the component and environment, enabling unsafe actions such as triggering sensitive operations or altering processing behavior.
Risk is conditional on deployments that implement distinct authorization levels for Restricted components; installations that do not differentiate authorization levels are described as not subject to this specific bypass because standard write permissions remain the effective security boundary. Upgrading to NiFi 2.8.0 is the recommended mitigation, and the issue was reported via responsible disclosure (credited to David Handermann in reporting). CVE records also reference public advisories and include a CVSS v4.0 vector indicating network reachability and high potential impact, while noting prerequisites such as the need for a privileged user to have already introduced the Restricted component into the flow.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Apache identified Apache NiFi 2.8.0 as the fixed version for CVE-2026-25903 and advised users to upgrade. The remediation closes the gap where restricted-status permissions were enforced during component addition but not during later updates.
Apache NiFi disclosed CVE-2026-25903, a missing authorization check flaw that lets lower-privileged users modify configuration properties of previously added Restricted components. The issue affects NiFi versions 1.1.0 through 2.7.2 and can enable unauthorized workflow or command-related changes depending on deployment permissions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.