THREAT OPS › Threat News › CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
<p>Posted by David Handermann on Aug 03</p>Severity: Medium <br /> <br /> Affected versions:<br /> <br /> - Apache NiFi (org.apache.nifi:nifi-web-api) 1.10.0 through 2.10.0<br /> <br /> Description:<br /> <br /> Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce <br /> authorization checking on components referencing Parameter values. Updatin
Indicators of compromise
- CVE-2026-68979cve
Original source: https://seclists.org/oss-sec/2026/q3/396