SCA: security update for org.apache.nifi:nifi-web-api (GHSA-c5w7-m8wf-xc77)

high Tenable Self-Hosted Container Security Plugin ID 437858

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on
extension components that have specific Required Permissions based on the Restricted annotation. The
Restricted annotation indicates additional privileges required to add the annotated component to the flow
configuration, but framework authorization did not check restricted status when updating a component
previously added. The missing authorization requires a more privileged user to add a restricted component
to the flow configuration, but permits a less privileged user to make property configuration changes.
Apache NiFi installations that do not implement different levels of authorization for Restricted
components are not subject to this vulnerability because the framework enforces write permissions as the
security boundary. Upgrading to Apache NiFi 2.8.0 is the recommended mitigation. (CVE-2026-25903)

See Also

https://github.com/advisories/GHSA-c5w7-m8wf-xc77

Plugin Details

Severity: High

ID: 437858

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 2/19/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.88

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:H/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2026-25903

CVSS v3

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 5.8

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 5.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/17/2026

Vulnerability Publication Date: 2/17/2026

Reference Information

CVE: CVE-2026-25903

cwe: CWE-862