PT-2026-67496 · Apache · Apache Nifi

·

CVE-2026-68980

·

Published

2026-08-03

·

Updated

2026-08-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi versions 2.0.0 through 2.10.0
Description Apache NiFi allows the creation, reading, and deletion of Assets associated with Parameter Contexts via the REST API. The framework authorizes asset deletion using the provided Parameter Context Identifier and Asset Identifier but fails to verify the requested Identifier against the stored Identifier. This issue affects installations that implement different levels of authorization across Parameter Contexts; those that do not are not affected as write permissions serve as the security boundary.
Recommendations Upgrade to Apache NiFi version 2.11.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2026-68980
CVE-2026-68980

Affected Products

Apache Nifi