CVE-2026-62354
Apache NiFi: incorrect authorization for Parameter Context validation requests
Technology
Apache NiFi
CVSS Score
4.3 / 10.0
Affected Versions
1.10.0 to 2.10.0
Upstream Fix
2.11.0
Published
August 3, 2026
OSSeva Coverage
Fixed upstream
Description
Users with only read access to a Parameter Context could submit validation requests with proposed parameter values, which override the current configuration and let them run component validation methods with other settings. Installations that do not separate read and write access to Parameter Contexts are not affected. Rated high by the NiFi project; NVD scores it 4.3. Fixed in 2.11.0, which requires write access for these requests.
Is your Apache NiFi deployment affected?
If you're running 1.10.0 to 2.10.0, you need this patch. Book a discovery call to get covered.