CVE-2026-62354
Last modified
CVE-2026-62354 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:L/U:Amber
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | >= 1.10.0, < 2.11.0 |
References
- https://lists.apache.org/thread/l17xcnnf1rm7qljmypyjxmh62cx4o4wjMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/08/03/11Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-62354?
How severe is CVE-2026-62354?
How do I fix CVE-2026-62354?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62348TDengine is a time-series database optimized for Internet of…5.4
- CVE-2026-62349TDengine is an open source, time-series database optimized f…8.3
- CVE-2026-6235The Sendmachine for WordPress plugin for WordPress is vulner…9.8
- CVE-2026-62350TDengine is an open source, time-series database optimized f…7.2
- CVE-2026-62351TDengine is a time-series database optimized for Internet of…7.5
- CVE-2026-62353TDengine is a time-series database optimized for Internet of…5.4
- CVE-2026-62355TDengine is an open source, time-series database optimized f…5.4
- CVE-2026-6236The Posts map plugin for WordPress is vulnerable to Stored C…6.4
- CVE-2026-62361listmonk is a standalone, self-hosted, newsletter and mailin…5.5
- CVE-2026-62363ImageMagick is free and open-source software used for editin…5
- CVE-2026-6237The Quick Table plugin for WordPress is vulnerable to Stored…6.4
- CVE-2026-62378RustFS Console is a web management console for the RustFS di…9
Are you affected by CVE-2026-62354?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
