CVE Explorer
CVE-2026-39816
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Script execution in the service prior to submitting the query. The missing Restricted annotation allows users without the Execute Code Permission to configure the Service in installations that use fine-gra
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.nifi:nifi-other-graph-services-nar","product":"Apache NiFi","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.8.0","status":"affected","version":"2.0.0-M1","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:262f75a566c2a050e83a594c9af99c69a8bf6cf7e67a3b4b797188e3b4147477 · sha256:756ab84d5315ba5a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"YES","Recovery":"IRRECOVERABLE","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.5,"baseSeverity":"HIGH","privilegesRequired":"HIGH","providerUrgency":"GREEN","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/AU:Y/R:I/V:C/RE:L/U:Green","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegr…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:262f75a566c2a050e83a594c9af99c69a8bf6cf7e67a3b4b797188e3b4147477 · sha256:756ab84d5315ba5a… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:262f75a566c2a050e83a594c9af99c69a8bf6cf7e67a3b4b797188e3b4147477 · sha256:756ab84d5315ba5a… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/04/13/8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:262f75a566c2a050e83a594c9af99c69a8bf6cf7e67a3b4b797188e3b4147477 · sha256:756ab84d5315ba5a… · /containers/adp/0/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/gh9g7xwvv4l20gzff6q3367snf35ctcb"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:262f75a566c2a050e83a594c9af99c69a8bf6cf7e67a3b4b797188e3b4147477 · sha256:756ab84d5315ba5a… · /containers/cna/references/0
{"url":"https://zeropath.com/blog/nifi-cve-2026-39816-privesc-rce"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:262f75a566c2a050e83a594c9af99c69a8bf6cf7e67a3b4b797188e3b4147477 · sha256:756ab84d5315ba5a… · /containers/adp/0/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.