CVE-2026-68980Patch(apache / nifi)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache nifi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-04); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-04: 1Mentions · 2026-08-12: 1Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-26: 108-0408-1208-26
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-041
Patch1
2026-08-121
Patch1
2026-08-261
Disclosure1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    Apache NiFi の 4件の脆弱性が FIX:コンフィグ設定の改竄やサービス拒否状態の恐れ https://iototsecnews.jp/2026/08/04/apache-nifi-vulnerabilities-enable-authorization-bypass-attacks/ Apache NiFi の Web API や Parameter Context における認可制御の不備などに起因する複数の脆弱性 (CVE-2026-62354/CVE-2026-68979/CVE-2026-68980/CVE-2026-68981) が確認されています。これらの欠陥を悪用されると、不正な設定変更やメモリ枯渇によるサービス停止、場合によってはコード実行を引き起こされる恐れがあります。システムを安全に利用するためにも、対象コンポーネントを最新版の Apache NiFi 2.11.0 へ速やかに更新し、アクセス権限や設定値の再確認を進めることが推奨されます。 #ApacheNiFi #CVE202662354 #CVE202668979 #CVE202668980 #CVE202668981 #Vulnerability #AuthNAuthZ #OpenSource

    Post summary

    The post reports four CVEs in Apache NiFi that enable authorization bypass, potentially causing config tampering, DoS, or code execution, and urges users to update to version 2.11.0.

    01000132
    507 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    Apache NiFiで、パラメータコンテキストの所有権を確かめずにアセットを削除できる欠陥。影響は2.0.0以上2.11.0未満です。評価が割れており、NVDの主評価は9.1 Criticalに対しApache自身のCVSS 4.0は2.3 Low。両方を載せています。 https://cve.autoarticles.net/cve/CVE-2026-68980

    Post summary

    The article reports CVE-2026-68980, a flaw in Apache NiFi that permits asset deletion without verifying parameter‑context ownership, affecting versions 2.0.0 to 2.11.0. It highlights a split in CVSS assessments (NVD 9.1 Critical vs Apache 2.3 Low) but gives no exploit or patch details.

    0000060
    562 followersView on X
  • TECHEPAGES@techepages
    Patch

    Apache has disclosed four security vulnerabilities in Apache NiFi affecting the Web API and Parameter Context authorization controls (versions 1.5.0–2.10.0). All issues are resolved in version 2.11.0. CVE-2026-68981 (High) — Improper enforcement of request size limits on gzip-compressed payloads, enabling memory exhaustion/DoS CVE-2026-62354 (High) — Authorization bypass allowing read-only users to influence component validation via crafted Parameter values CVE-2026-68979 (Medium) — Missing authorization checks on components referencing updated Parameter Contexts; potential code execution in specific configurations CVE-2026-68980 (Low) — Insufficient ownership verification during Asset deletion Organizations running affected versions are advised to upgrade to NiFi 2.11.0

    Post summary

    Apache disclosed four NiFi vulnerabilities, all fixed in version 2.11.0, and recommends upgrading to that version.

    0000039
    35 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more