CVE-2026-87976
nifi: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-87976)
Description
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
0.4.0Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-21 14:14 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- CPE Configuration: OR *cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* versions from (including) 0.4.0 up to (excluding) 2.12.0
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/kw89toml5zq20ry3279mx7y184vrlb8x Types: Mailing List, Vendor Advisory
- Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/09/16/11 Types: Mailing List, Third Party Advisory
- CVE Modified2026-09-17 20:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-87976","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-09-16 21:17 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/09/16/11
- New CVE Received2026-09-16 20:17 UTC· security@apache.org
- Description: Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:X/U:X
- CWE: CWE-22
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/87xxx/CVE-2026-87976.json">CVE-2026-87976</a>