Improper access control in Apache Nifi - CVE-2026-68980
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to delete assets associated with other parameter contexts.
The vulnerability exists due to improper access control in the parameter context asset deletion REST API when handling asset deletion requests using a supplied parameter context identifier and asset identifier. A remote user can submit a crafted deletion request with mismatched identifiers to delete assets associated with other parameter contexts.
Only installations that implement different authorization levels across parameter contexts are affected.