Authorization Flaw in Apache NiFi Affects Asset Management Functionality
CVE-2026-68980
What is CVE-2026-68980?
Apache NiFi versions 2.0.0 through 2.10.0 contain an authorization vulnerability that affects the creation, reading, and deletion of Assets linked to Parameter Contexts via the REST API. The issue arises from the insecurity of asset deletion operations, where the framework relies solely on the supplied Parameter Context Identifier without cross-verifying it against the stored Identifier. Systems with properly implemented authorization across Parameter Contexts are not impacted, as they maintain robust security boundaries by enforcing write permissions. To mitigate this vulnerability, it is recommended to upgrade to Apache NiFi version 2.11.0 or later, which enhances security by verifying Parameter Context ownership for asset deletions.
Affected Version(s)
Apache NiFi 2.0.0 <= 2.10.0