Apache NiFi 1.1.0 through 2.7.2 fails to enforce Restricted-annotation based authorization when updating configuration properties on extension components that have Required Permissions derived from the @Restricted annotation. While NiFi correctly requires elevated privileges to add a Restricted component to a flow, the framework did not re-check the component’s restricted status during subsequent property updates of an already-added component. This missing authorization allows a less-privileged user to modify configuration properties of Restricted components after a more-privileged user has added them. Deployments that do not implement differentiated authorization levels for Restricted components are stated to not be subject to this issue because write permissions remain the effective security boundary.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
High-severity authorization bypass in Apache NiFi caused by missing authorization checks when updating configuration properties of Restricted extension components, allowing lower-privileged users to modify restricted components after they were added by a privileged user.
A missing-authorization flaw in Apache NiFi (1.1.0–2.7.2) where the framework fails to check Restricted status when updating configuration properties of already-added Restricted-annotated extension components, allowing a less-privileged user to modify properties that should require higher privileges.
Authorization bypass in Apache NiFi where restricted-status checks are not enforced on updates to already-added restricted components, allowing less-privileged users to change configuration properties.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.