Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does…

Technology

Apache NiFi

CVSS Score

9.8 / 10.0

Affected Versions

>=1.10.0 <2.11.0

Upstream Fix

See upstream advisory

Published

August 3, 2026

OSSeva Coverage

Fixed upstream

Description

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting con

Is your Apache NiFi deployment affected?

If you're running >=1.10.0 <2.11.0, you need this patch. Book a discovery call to get covered.