Skip to main content
EPSS 0.3%top 75%

CVE-2026-68980: CWE-863 Incorrect Authorization in Apache Software Foundation Apache NiFi

0
Critical
Published: 08/17/2026 (08/17/2026, 05:49:54 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache NiFi

Description

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

CVSS v4.0

Score 2.3low

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
Scope
N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:L/U:Clear

Affected software

Apache Software Foundation

Apache NiFi

Affected versions
>=2.0.0 <=2.10.0
org.apache.nifi/nifi
pkg:maven/org.apache.nifi/nifi
Affected versions
=2.0.0<=2.10.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 18:08:41 UTC

Technical Analysis

Apache NiFi 2.0.0 through 2.10.0 allow creating, reading, and deleting Assets linked to Parameter Contexts via the REST API. The authorization check for asset deletion only verifies the supplied Parameter Context Identifier but does not confirm that the Asset Identifier belongs to that Parameter Context. This incorrect authorization (CWE-863) can allow users with write permissions on one Parameter Context to delete assets from another if authorization boundaries are not properly segregated. The vulnerability is mitigated in Apache NiFi 2.11.0, which adds verification of Parameter Context ownership of the Asset before allowing deletion, using the same approach as for asset read operations.

Potential Impact

The vulnerability allows users with write permissions on a Parameter Context to potentially delete assets associated with other Parameter Contexts if different authorization levels are not enforced across contexts. This could lead to unauthorized asset deletion, impacting data integrity and operational stability. However, installations that implement distinct authorization boundaries per Parameter Context are not affected. The CVSS 4.0 base score is low (2.3), reflecting limited impact and attack complexity.

Mitigation Recommendations

Upgrade Apache NiFi to version 2.11.0 or later, where the vulnerability is fixed by verifying Parameter Context ownership of the requested Asset before deletion. No other official remediation or temporary fixes are documented. Since this is a software vulnerability in on-premises deployments, users must apply the update manually. Installations that already enforce strict authorization boundaries per Parameter Context are not vulnerable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-01T20:13:02.779Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a70f79ebf32cb7a34248235

Added to database: 08/03/2026, 20:18:38 UTC

Last enriched: 08/11/2026, 18:08:41 UTC

Last updated: 09/17/2026, 22:01:37 UTC

Views: 51

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses