x.com/ZeroPathAI/status/2053867743921713448
1 correction found
Prior to version 2.9.0
Apache does not say all pre-2.9.0 NiFi versions are affected. The official advisory says CVE-2026-39816 affects NiFi 2.0.0-M1 through 2.8.0.
Full reasoning
This version range is too broad.
Apache NiFi's official security page lists affected versions as 2.0.0-M1 to 2.8.0 and fixed versions as 2.9.0 for CVE-2026-39816. Apache's public oss-security disclosure says the same thing: Apache NiFi ... 2.0.0-M1 through 2.8.0.
So while upgrading to 2.9.0 is the recommended fix, it is not correct to describe the issue as affecting all versions prior to 2.9.0. That wording incorrectly sweeps in older NiFi releases outside the documented affected range, including 1.x releases, which Apache does not list as affected by this CVE.
2 sources
- Security Reporting - Apache NiFi
CVE-2026-39816 ... Affected Versions: 2.0.0-M1 to 2.8.0 ... Fixed Versions: 2.9.0 ... Upgrading to Apache NiFi 2.9.0 is the recommended mitigation.
- oss-security - CVE-2026-39816: Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService
Affected versions: - Apache NiFi (org.apache.nifi:nifi-other-graph-services-nar) 2.0.0-M1 through 2.8.0