Improper access control in Apache Nifi - CVE-2026-68980

 

Improper access control in Apache Nifi - CVE-2026-68980

Published: August 24, 2026


Vulnerability identifier: #VU144806
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68980
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete assets associated with other parameter contexts.

The vulnerability exists due to improper access control in the parameter context asset deletion REST API when handling asset deletion requests using a supplied parameter context identifier and asset identifier. A remote user can submit a crafted deletion request with mismatched identifiers to delete assets associated with other parameter contexts.

Only installations that implement different authorization levels across parameter contexts are affected.


Affected software

Apache Nifi

How to mitigate CVE-2026-68980

Install security update from vendor's website.

Apache Nifi - update to 2.11.0

External References

Related Security Bulletins