Improper access control in Apache Nifi - CVE-2026-62354
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to invoke predefined component validation methods with alternative settings.
The vulnerability exists due to improper access control in Parameter Context validation requests when handling validation submissions with proposed Parameter values. A remote user can submit proposed Parameter values to invoke predefined component validation methods with alternative settings.
Only installations that implement different authorization levels for viewing and modifying Parameter Context configuration are vulnerable.