Authorization Bypass in Apache NiFi Affects Multiple Versions
CVE-2026-68979
5.9MEDIUM
What is CVE-2026-68979?
The Apache NiFi software versions 1.10.0 to 2.10.0 contain a vulnerability in the Parameter Context update REST API method that fails to enforce proper authorization checks. An authenticated user with the ability to modify a Parameter Context could inadvertently or maliciously alter Parameter values affecting other components that rely on these values, potentially leading to unauthorized code execution during automatic validations. This issue is particularly acute in environments utilizing component-level authorization policies. To mitigate this vulnerability, it is critical for users to update to Apache NiFi version 2.11.0 or later, which enhances authorization checks for affected components.
Affected Version(s)
Apache NiFi 1.10.0 <= 2.10.0