Apache NiFi fixed CVE-2026-39816, a high-severity flaw that lets authenticated users execute arbitrary code without the EXECUTE_CODE permission when certain optional graph extensions are installed, particularly nifi-other-graph-services-nar. The issue affects NiFi versions 2.0.0-M1 through 2.8.0 and stems from the TinkerpopClientService, which can compile and run user-supplied Groovy code before submitting a graph query. Apache attributed the bug to a missing restricted annotation tied to the Execute Code required permission, creating a privilege-boundary bypass in deployments using TinkerPop graph query features.
The vulnerability was reported by John Walker of ZeroPath and tracked as NIFI-15800, with Apache addressing it in NiFi 2.9.0. ZeroPath said the flaw reflects a mismatch in NiFi’s privilege model, where graph query functionality was not treated as a code-execution path even though TinkerPop’s native query mode can trigger server-side code execution; the researchers also published a proof of concept showing shell access on a vulnerable server. Organizations running affected NiFi deployments are advised to upgrade to 2.9.0 or later or remove the impacted optional graph-related NAR extensions if an upgrade cannot be completed immediately.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
ZeroPath publicly disclosed CVE-2026-39816 as a high-severity Apache NiFi flaw affecting deployments with optional graph-related NAR extensions, especially nifi-other-graph-services-nar. The disclosure included technical details and a proof of concept showing arbitrary code execution and recommended upgrading to NiFi 2.9.0 or removing the affected extensions.
Apache addressed the vulnerability in Apache NiFi 2.9.0. The fix corrected the missing restricted annotation tied to the Execute Code required permission, remediating affected versions 2.0.0-M1 through 2.8.0 in vulnerable configurations.
ZeroPath Research reported the Apache NiFi vulnerability later assigned CVE-2026-39816 and tracked as NIFI-15800. The issue involved a permission-boundary bypass that could let authenticated users without EXECUTE_CODE run Groovy code when affected graph extensions were installed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bugflation.com
Open sourcezeropath.com
Open sourcecyberpress.org
Open sourcegbhackers.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.