← All Advisories

Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.0

Status: UPDATED  |  Advisory ID: CVE-2026-68980

Key Details

CVECVE-2026-68980
CVSS Score / Version9.1 (Critical) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsApache nifi
Classified asCWE-863 (Incorrect Authorization)
Exploitation prediction (EPSS)0.32% probability of exploitation in the next 30 days (25% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apachenifi
SubsystemsGeneral OT
SectorsMultiple

What to Know

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

What to Do

Monitor Apache's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68980
Vendor advisoryhttps://lists.apache.org/thread/yo8k6tt3zxjm49zzhly3453v0xhwm3o1