PT-2026-67494 · Apache · Apache Nifi

CVE-2026-62354

·

Published

2026-08-03

·

Updated

2026-08-17

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y/R:I/V:C/RE:L/U:Amber
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 1.10.0 through 2.10.0
Description Authorization handling for Parameter Context validation requests allows clients with read access to submit proposed Parameter values. These proposed values override the current configuration, enabling users with read access to invoke predefined component validation methods using alternative settings. This issue does not affect installations that do not implement different authorization levels for viewing and modifying Parameter Context configuration.
Recommendations Upgrade to Apache NiFi version 2.11.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2026-62354
CVE-2026-62354

Affected Products

Apache Nifi