Improper access control in Apache Nifi - CVE-2026-62354

 

Improper access control in Apache Nifi - CVE-2026-62354

Published: August 24, 2026


Vulnerability identifier: #VU144805
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62354
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to invoke predefined component validation methods with alternative settings.

The vulnerability exists due to improper access control in Parameter Context validation requests when handling validation submissions with proposed Parameter values. A remote user can submit proposed Parameter values to invoke predefined component validation methods with alternative settings.

Only installations that implement different authorization levels for viewing and modifying Parameter Context configuration are vulnerable.


Affected software

Apache Nifi

How to mitigate CVE-2026-62354

Install security update from vendor's website.

Apache Nifi - update to 2.11.0

External References

Related Security Bulletins