Threat Advisory

Apache NiFi Flaws Expose Data Pipelines to File System Manipulation and Denial of Service

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Apache NiFi versions and Mitigation have been identified in Apache NiFi and MyFaces. The flaws expose enterprise data pipelines and web applications to file system manipulation and Denial of Service attacks. Affected version ranges include NiFi Registry 0.4.0 through 2.11.0 and NiFi 2.11.0, while the MyFaces flaw impacts branches 2.2.0 through 4.1.3.

CVE-2026-87976 (CVSS 7.2 — High severity): The first of the Apache NiFi vulnerabilities involves improper limitation of pathnames in persisted extension bundles. Authenticated users authorized to write and delete bundles can upload a NAR with a crafted manifest, resulting in file operations outside of the designated directory.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Apache NiFi versions and Mitigation have been identified in Apache NiFi and MyFaces. The flaws expose enterprise data pipelines and web applications to file system manipulation and Denial of Service attacks. Affected version ranges include NiFi Registry 0.4.0 through 2.11.0 and NiFi 2.11.0, while the MyFaces flaw impacts branches 2.2.0 through 4.1.3.

CVE-2026-87976 (CVSS 7.2 — High severity): The first of the Apache NiFi vulnerabilities involves improper limitation of pathnames in persisted extension bundles. Authenticated users authorized to write and delete bundles can upload a NAR with a crafted manifest, resulting in file operations outside of the designated directory.[emaillocker id="1283"]

CVE-2026-70469: The framework failed to properly validate multiple instances of the Content-Encoding header or reject non-standard gzip identifiers. A malicious client can send crafted requests to consume excessive memory, leading to a crash.

CVE-2026-76646 (CVSS 7.2 — High severity): A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition.

These vulnerabilities collectively present significant risks for enterprise data pipelines and web applications.

RECOMMENDATION:

We recommend you to upgrade MyFaces to version 2.3.12, 3.0.4, 4.0.4, or 4.1.4 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu