CVE-2026-39816 is an authorization-bypass vulnerability in Apache NiFi 2.0.0-M1 through 2.8.0. The optional TinkerpopClientService lacks the Restricted annotation requiring the Execute Code permission. A user who is not authorized to execute code can configure the service for bytecode submission and provide a Groovy graph query. The graph-query execution path compiles and evaluates the Groovy input locally before submitting the graph traversal, bypassing NiFi's intended Execute Code authorization boundary.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 34-file repository is a multi-CVE offensive research collection for Keycloak, Apache NiFi, HashiCorp Vault, and HashiCorp Nomad. It contains four standalone Python PoCs under exploits/, three corresponding Metasploit modules under metasploit-custom-modules/, module documentation, and four deliberately vulnerable Docker labs under docker-lab/. The Metasploit modules provide reusable Keycloak account takeover, Vault secret disclosure, and NiFi command/reverse-shell exploitation; Nomad is supplied as a standalone PoC only. The labs bind their primary services to localhost and intentionally use vulnerable versions: Keycloak 26.7.1, NiFi 2.8.0 with graph NARs and Keycloak OIDC, Vault 2.0.3 dev mode, and Nomad 2.0.0 with a privileged nested Docker/client setup. Notable implementation issue: exploits/nifi_rce_39816.py imports nifi_oidc from a repository-root configs directory, but the supplied nifi_oidc.py is actually located in docker-lab/nifi-cve-2026-39816/setup/; absent an external configs/nifi_oidc.py, that standalone script will fail at import time. The equivalent Metasploit NiFi module contains its own OIDC implementation and is not affected by this path mismatch.
Repository contains a working proof-of-concept for CVE-2026-39816 against Apache NiFi 2.8.0. The main exploit is pocs/flow_designer_groovy_rce.py, a standalone Python script that authenticates to the NiFi REST API, verifies that the low-privileged user lacks access to restricted scripting processors, then abuses the unrestricted ExecuteGraphQuery/TinkerpopClientService path to execute attacker-supplied Groovy in the NiFi JVM. Its practical payload is a reverse shell callback to the operator, followed by PTY upgrade and interactive terminal handling. This is not merely a detector; it performs end-to-end exploitation and cleanup. Repository structure is split between the exploit and a reproducible lab environment. The setup/ directory provisions a Docker Compose stack with Apache NiFi 2.8.0, OpenLDAP, and a Gremlin server. Supporting files configure LDAP-backed authentication and NiFi authorization, seed two users (admin and flow_designer), patch NiFi properties, and automate startup/teardown. setup.sh also downloads the required graph bundle NARs from Maven Central and configures policies so flow_designer has flow-editing rights but not EXECUTE_CODE, matching the intended bypass scenario. Primary attack vector is web/network-based via authenticated HTTPS access to NiFi's /nifi-api endpoints. The exploit depends on the optional graph bundle being installed and on the attacker having sufficient design permissions to create controller services/processors. Fingerprintable infrastructure includes the NiFi API at /nifi-api/access/token and /flow/process-groups/root, LDAP at ldap://ldap:389, Gremlin at gremlin-server:8182 / ws://gremlin-server:8182/gremlin, Maven Central for NAR downloads, and the reverse-shell callback target host.docker.internal:9998. Overall, this repository is a realistic operational POC demonstrating privilege-boundary bypass leading to arbitrary code execution as the NiFi service account.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authorization-bypass remote code execution vulnerability in Apache NiFi's TinkerpopClientService and ExecuteGraphQuery/ExecuteGraphQueryRecord processors. A user with process-group and controller read/write permissions, but explicitly denied Execute Code, can submit Groovy that is compiled and executed by the local GremlinGroovyScriptEngine as the NiFi service account.
A high-severity Apache NiFi vulnerability caused by a missing restricted annotation for the Execute Code Required Permission, allowing users without EXECUTE_CODE permission to configure TinkerpopClientService to execute Groovy code when the optional graph services extension is installed.
A high-severity authenticated arbitrary code execution vulnerability in Apache NiFi that allows users lacking the EXECUTE_CODE privilege to run Groovy code on the NiFi server via graph query functionality when optional graph-related extensions, including nifi-other-graph-services-nar, are installed.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.