THREAT OPS › Threat News › CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
<p>Posted by David Handermann on Aug 03</p>Severity: Low <br /> <br /> Affected versions:<br /> <br /> - Apache NiFi (org.apache.nifi:nifi-web-api) 2.0.0 through 2.10.0<br /> <br /> Description:<br /> <br /> Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts <br /> through the REST API. The framework authorizes asset deletion against
Indicators of compromise
- CVE-2026-68980cve
Original source: https://seclists.org/oss-sec/2026/q3/398