CVE-2026-39816

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
08/05/2026
Last modified:
09/05/2026

Description

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Script execution in the service prior to submitting the query. The missing Restricted annotation allows users without the Execute Code Permission to configure the Service in installations that use fine-grained authorization and have the optional TinkerpopClientService installed. Apache NiFi installations that do not have the nifi-other-graph-services-nar installed are not subject to this vulnerability. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:* 2.0.0 (including) 2.9.0 (excluding)