Authorization Bypass in Apache NiFi Affects Multiple Versions
CVE-2026-68979

5.9MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
3 August 2026

What is CVE-2026-68979?

The Apache NiFi software versions 1.10.0 to 2.10.0 contain a vulnerability in the Parameter Context update REST API method that fails to enforce proper authorization checks. An authenticated user with the ability to modify a Parameter Context could inadvertently or maliciously alter Parameter values affecting other components that rely on these values, potentially leading to unauthorized code execution during automatic validations. This issue is particularly acute in environments utilizing component-level authorization policies. To mitigate this vulnerability, it is critical for users to update to Apache NiFi version 2.11.0 or later, which enhances authorization checks for affected components.

Affected Version(s)

Apache NiFi 1.10.0 <= 2.10.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D0HY30N
.