Description
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows authenticated users with permission to write and delete bundles to cause file system operations outside the designated persistence directory by uploading a NAR bundle with a crafted manifest. This path manipulation results from the path‑containment check using an unnormalised resolved path and permitting parent‑directory names in the group, artifact, and version coordinates. Because the bad path is accepted, an attacker can write, overwrite, or delete arbitrary files on the host filesystem, potentially affecting critical system or application files.

Affected Systems

Apache NiFi Registry versions 0.4.0 through 2.11.0 are affected. The product is the Apache NiFi Registry component of the Apache Software Foundation’s NiFi suite. Upgrading to version 2.12.0 or later provides the fix that rejects parent‑directory coordinates and enforces normalization of the storage path.

Risk and Exploitability

The severity is assessed with a CVSS score of 7.2, indicating a high impact. The EPSS score is below 1 %, implying that the probability of exploitation is low at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires valid credentials with write/delete rights to a bucket and the ability to upload an extension bundle. The attack path is local and authenticated, with filesystem access and the ability to manipulate storage paths.

Generated by OpenCVE AI on September 18, 2026 at 02:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache NiFi Registry to version 2.12.0 or newer to apply the path‑normalization fix.
  • Revoke write and delete permissions for buckets from any user that should not be able to upload extension bundles.
  • Monitor bundle upload activity for anomalous manifests and review logs for evidence of path‑manipulation attempts.

Generated by OpenCVE AI on September 18, 2026 at 02:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache nifi
CPEs cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
Vendors & Products Apache nifi
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache nifi Registry
Vendors & Products Apache
Apache nifi Registry

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.
Title Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y/R:U/V:C'}


Subscriptions

Apache Nifi Nifi Registry
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-17T19:13:23.645Z

Reserved: 2026-09-09T18:20:30.141Z

Link: CVE-2026-87976

cve-icon Vulnrichment

Updated: 2026-09-17T19:13:19.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T20:17:38.320

Modified: 2026-09-21T14:14:51.633

Link: CVE-2026-87976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:01Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')