Severity: Medium 

Affected versions:

- Apache NiFi (org.apache.nifi:nifi-web-api) 1.10.0 through 2.10.0

Description:

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API 
method that does not enforce authorization checking on components referencing 
Parameter values. Updating a Parameter Context can change parameter values that 
affect referencing components, but framework authorization was limited to read 
and write privileges on the Parameter Context itself. As a result of the 
missing authorization, an authenticated user authorized to modify a Parameter 
Context, but not authorized on referencing components, could alter Parameter 
values affecting those components. In deployments where a Parameter value 
contains executable scripting content, updating a Parameter can result in code 
execution during automatic component validation, without starting the 
referencing component. The impact was limited to stopped components by existing 
verification checks, and the issue applies only to deployments that use 
component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the 
recommended mitigation, which aligns the Parameter Context update method 
authorization with other methods, adding authorization checking on affected 
components.

This issue is being tracked as NIFI-16148 

Credit:

D0HY30N (finder)

References:

https://nifi.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-68979
https://issues.apache.org/jira/browse/NIFI-16148

Timeline:

2026-07-22: reported

Reply via email to