CVE-2026-62354Disclosure(apache / nifi)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache nifi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-04: 3Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-04: 3Technical Details · 2026-08-12: 108-0408-12
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-043
Disclosure3
2026-08-121
Patch1
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption. #ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec http://securityonline.info/apache-nifi-vulnerabilities/

    Post summary

    The post announces several Apache NiFi CVEs, highlighting code execution and resource consumption impacts, but offers no PoC, exploit, or mitigation information.

    01040453
    12.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache NiFi の 4件の脆弱性が FIX:コンフィグ設定の改竄やサービス拒否状態の恐れ https://iototsecnews.jp/2026/08/04/apache-nifi-vulnerabilities-enable-authorization-bypass-attacks/ Apache NiFi の Web API や Parameter Context における認可制御の不備などに起因する複数の脆弱性 (CVE-2026-62354/CVE-2026-68979/CVE-2026-68980/CVE-2026-68981) が確認されています。これらの欠陥を悪用されると、不正な設定変更やメモリ枯渇によるサービス停止、場合によってはコード実行を引き起こされる恐れがあります。システムを安全に利用するためにも、対象コンポーネントを最新版の Apache NiFi 2.11.0 へ速やかに更新し、アクセス権限や設定値の再確認を進めることが推奨されます。 #ApacheNiFi #CVE202662354 #CVE202668979 #CVE202668980 #CVE202668981 #Vulnerability #AuthNAuthZ #OpenSource

    Post summary

    The article announces four CVEs in Apache NiFi, details the exploit risks, and urges users to patch to version 2.11.0 to mitigate potential unauthorized configuration changes, service denial, or code execution.

    01000132
    507 followersView on X
  • VulniPulse@vulnipulse
    Disclosure

    ⚠️ HIGH CVE ALERT CVE-2026-62354 · Apache NiFi · CVSS 7.7 Users with read access could submit proposed Parameter values that override current configuration. 🔎 Full advisory: https://vulnipulse.com/advisories/apache-cve-2026-62354 #CyberSecurity #CVE #Apache #ApacheNiFi

    Post summary

    The post announces CVE-2026-62354, a medium‑severe flaw in Apache NiFi where users with read access can override configuration settings; a full advisory is linked, but no exploitation details or patches are discussed.

    1000057
    7 followersView on X
  • TECHEPAGES@techepages
    Disclosure

    Apache has disclosed four security vulnerabilities in Apache NiFi affecting the Web API and Parameter Context authorization controls (versions 1.5.0–2.10.0). All issues are resolved in version 2.11.0. CVE-2026-68981 (High) — Improper enforcement of request size limits on gzip-compressed payloads, enabling memory exhaustion/DoS CVE-2026-62354 (High) — Authorization bypass allowing read-only users to influence component validation via crafted Parameter values CVE-2026-68979 (Medium) — Missing authorization checks on components referencing updated Parameter Contexts; potential code execution in specific configurations CVE-2026-68980 (Low) — Insufficient ownership verification during Asset deletion Organizations running affected versions are advised to upgrade to NiFi 2.11.0

    Post summary

    Apache disclosed four CVEs affecting NiFi’s Web API and Parameter Context authorization controls, detailed each vulnerability’s nature and severity, and provided a patch (NiFi 2.11.0) for remediation.

    0000039
    35 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more