Authorization Flaw in Apache NiFi Allows Unauthorized Parameter Modifications
CVE-2026-62354

7.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
3 August 2026

What is CVE-2026-62354?

The vulnerability in Apache NiFi pertains to inadequate authorization measures for Parameter Context validation requests, which affects versions from 1.10.0 to 2.10.0. Clients with merely read access can submit proposed Parameter values that override existing configurations. This poses significant risks as it allows unauthorized manipulation of component validation methods, potentially leading to unintended system behaviors. For enhanced security, it is crucial to upgrade to Apache NiFi version 2.11.0 or later, which enforces stricter access controls requiring write access for submitting Parameter Context validation requests.

Affected Version(s)

Apache NiFi 1.10.0 <= 2.10.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Van Hiep from MBBank
.