- Description
- Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- nifi
CVSS 4.0
- Type
- Secondary
- Base score
- 7.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:L/U:Amber
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- security@apache.org
- CWE-863
- Hype score
- Not currently trending
⚠️ HIGH CVE ALERT CVE-2026-62354 · Apache NiFi · CVSS 7.7 Users with read access could submit proposed Parameter values that override current configuration. 🔎 Full advisory: https://t.co/GCHvvg8K0M #CyberSecurity #CVE #Apache #ApacheNiFi
@vulnipulse
4 Aug 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption. #ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec https://t.co/3OCdMPb1PO
@Daily_CyberSec
4 Aug 2026
409 Impressions
1 Retweet
4 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*",
"matchCriteriaId": "62B90D58-2E7A-47A1-BAB4-92F7D88C4F49",
"versionEndExcluding": "2.11.0",
"versionStartIncluding": "1.10.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]