Authorization Flaw in Apache NiFi Allows Unauthorized Parameter Modifications
CVE-2026-62354
7.7HIGH
What is CVE-2026-62354?
The vulnerability in Apache NiFi pertains to inadequate authorization measures for Parameter Context validation requests, which affects versions from 1.10.0 to 2.10.0. Clients with merely read access can submit proposed Parameter values that override existing configurations. This poses significant risks as it allows unauthorized manipulation of component validation methods, potentially leading to unintended system behaviors. For enhanced security, it is crucial to upgrade to Apache NiFi version 2.11.0 or later, which enforces stricter access controls requiring write access for submitting Parameter Context validation requests.
Affected Version(s)
Apache NiFi 1.10.0 <= 2.10.0