← All Advisories

CVE-2026-87976

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-87976

Key Details

CVECVE-2026-87976
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productsApache NiFi and Apache Software Foundation Apache NiFi Registry
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
ApacheNiFi
Apache Software FoundationApache NiFi Registry
SubsystemsGeneral OT
SectorsMultiple

What to Know

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location. (NVD)

What to Do

Monitor Apache's and Apache Software Foundation's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-87976
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-87976
Vendor advisoryhttps://lists.apache.org/thread/kw89toml5zq20ry3279mx7y184vrlb8x