Authorization Flaw in Apache NiFi Affects Asset Management Functionality
CVE-2026-68980

2.3LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
3 August 2026

What is CVE-2026-68980?

Apache NiFi versions 2.0.0 through 2.10.0 contain an authorization vulnerability that affects the creation, reading, and deletion of Assets linked to Parameter Contexts via the REST API. The issue arises from the insecurity of asset deletion operations, where the framework relies solely on the supplied Parameter Context Identifier without cross-verifying it against the stored Identifier. Systems with properly implemented authorization across Parameter Contexts are not impacted, as they maintain robust security boundaries by enforcing write permissions. To mitigate this vulnerability, it is recommended to upgrade to Apache NiFi version 2.11.0 or later, which enhances security by verifying Parameter Context ownership for asset deletions.

Affected Version(s)

Apache NiFi 2.0.0 <= 2.10.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mak3bread (Minseong Kim)
.