Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-62354

Apache NiFi: incorrect authorization for Parameter Context validation requests

Technology

Apache NiFi

CVSS Score

4.3 / 10.0

Affected Versions

1.10.0 to 2.10.0

Upstream Fix

2.11.0

Published

August 3, 2026

OSSeva Coverage

Fixed upstream

Description

Users with only read access to a Parameter Context could submit validation requests with proposed parameter values, which override the current configuration and let them run component validation methods with other settings. Installations that do not separate read and write access to Parameter Contexts are not affected. Rated high by the NiFi project; NVD scores it 4.3. Fixed in 2.11.0, which requires write access for these requests.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.10.0 to 2.10.0, you need this patch. Book a discovery call to get covered.