THREATOPS
THREAT OPSThreat News › CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests

CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests

medoss_secPublished 2026-08-03

<p>Posted by David Handermann on Aug 03</p>Severity: High <br /> <br /> Affected versions:<br /> <br /> - Apache NiFi (org.apache.nifi:nifi-web-api) 1.10.0 through 2.10.0<br /> <br /> Description:<br /> <br /> Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients <br /> with read access to submit proposed Parameter values. The proposed

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/397