CVE-2026-68979Patch(apache / nifi)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache nifi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-04); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-08-03: 1Mentions · 2026-08-04: 2Mentions · 2026-08-12: 1Mentions · 2026-08-24: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-04: 2Technical Details · 2026-08-12: 1Technical Details · 2026-08-24: 108-0308-0408-1208-24
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-031
Disclosure1
2026-08-042
Disclosure1Patch1
2026-08-121
Patch1
2026-08-241
Patch1
Full discourse5 posts
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption. #ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec http://securityonline.info/apache-nifi-vulnerabilities/

    Post summary

    A brief disclosure of several Apache NiFi CVEs that could enable remote code execution and cause high resource consumption.

    01040453
    12.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache NiFi の 4件の脆弱性が FIX:コンフィグ設定の改竄やサービス拒否状態の恐れ https://iototsecnews.jp/2026/08/04/apache-nifi-vulnerabilities-enable-authorization-bypass-attacks/ Apache NiFi の Web API や Parameter Context における認可制御の不備などに起因する複数の脆弱性 (CVE-2026-62354/CVE-2026-68979/CVE-2026-68980/CVE-2026-68981) が確認されています。これらの欠陥を悪用されると、不正な設定変更やメモリ枯渇によるサービス停止、場合によってはコード実行を引き起こされる恐れがあります。システムを安全に利用するためにも、対象コンポーネントを最新版の Apache NiFi 2.11.0 へ速やかに更新し、アクセス権限や設定値の再確認を進めることが推奨されます。 #ApacheNiFi #CVE202662354 #CVE202668979 #CVE202668980 #CVE202668981 #Vulnerability #AuthNAuthZ #OpenSource

    Post summary

    The post announces four CVEs in Apache NiFi that could lead to unauthorized configuration changes and possibly code execution, recommending a swift update to version 2.11.0 as the mitigation.

    01000132
    507 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    Apache NiFi のパラメータコンテキスト更新が、参照先コンポーネントの認可を検査していませんでした。対象は1.10.0から2.10.0、修正は2.11.0です。深刻度はApacheが5.9、NVDが9.8と割れています。読み方を整理しました。 https://cve.autoarticles.net/cve/CVE-2026-68979

    Post summary

    CVE-2026-68979 is an authorization bypass in Apache NiFi affecting versions 1.10.0‑2.10.0; it is fixed in 2.11.0 and carries a high severity rating.

    0000054
    562 followersView on X
  • TECHEPAGES@techepages
    Patch

    Apache has disclosed four security vulnerabilities in Apache NiFi affecting the Web API and Parameter Context authorization controls (versions 1.5.0–2.10.0). All issues are resolved in version 2.11.0. CVE-2026-68981 (High) — Improper enforcement of request size limits on gzip-compressed payloads, enabling memory exhaustion/DoS CVE-2026-62354 (High) — Authorization bypass allowing read-only users to influence component validation via crafted Parameter values CVE-2026-68979 (Medium) — Missing authorization checks on components referencing updated Parameter Contexts; potential code execution in specific configurations CVE-2026-68980 (Low) — Insufficient ownership verification during Asset deletion Organizations running affected versions are advised to upgrade to NiFi 2.11.0

    Post summary

    The notice announces four high‑severity vulnerabilities in Apache NiFi and recommends upgrading to version 2.11.0 to patch the issues, providing technical details but no exploit evidence.

    0000039
    35 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-68979](https://lists.apache.org/thread/xwz8wsss2ovx07tns96rkc3n7cm4xfrq) Apache NiFI 1.... https://lists.apache.org/thread/xwz8wsss2ovx07tns96rkc3n7cm4xfrq #PatchManagement #Vulnerability #CVE

    Post summary

    The post announces the existence of CVE‑2026‑68979 in Apache NiFi, pointing to a mailing‑list thread for details, but provides no further technical or remedial information.

    0000034
    18 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more