<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Apache-Nifi — PoC Archive</title><link>https://poc.intelseclab.com/tags/apache-nifi/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/apache-nifi/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39816-apache-nifi-groovy-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39816-apache-nifi-groovy-rce/</guid><description>Critical severity — web · CVE-2026-39816. Status: Weaponized. Affects: Apache NiFi (with the optional graph bundle / nifi-other-graph-services-nar). Tags: apache-nifi, groovy, code-injection, privilege-escalation, rce, graph-bundle, authenticated.</description><category>web</category><category>Critical</category><category>apache-nifi</category><category>groovy</category><category>code-injection</category><category>privilege-escalation</category><category>rce</category><category>graph-bundle</category><category>authenticated</category></item></channel></rss>