CVE-2026-68980
Last modified
CVE-2026-68980 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Clear
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | >= 2.0.0, < 2.11.0 |
References
- https://lists.apache.org/thread/yo8k6tt3zxjm49zzhly3453v0xhwm3o1Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/08/03/12Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-68980?
How severe is CVE-2026-68980?
How do I fix CVE-2026-68980?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68969Apache Airflow wrote Variable values and Connection `extra` …
- CVE-2026-6897The Wishlist Member plugin for WordPress is vulnerable to un…8.8
- CVE-2026-68970Apache Airflow's Task SDK did not mask the contents of a Var…
- CVE-2026-68971Apache Airflow's asset materialization endpoint (`POST /api/…
- CVE-2026-68979Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Contex…9.8
- CVE-2026-6898The Wishlist Member plugin for WordPress is vulnerable to un…8.8
- CVE-2026-68981Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP r…7.5
- CVE-2026-6899Check for certificate revocation only considers the first ma…5.6
- CVE-2026-6900Improper certificate validation vulnerability in B&R Industr…9.1
- CVE-2026-6901Untrusted Search Path vulnerability in B&R Industrial Automa…8.4
- CVE-2026-6902A Remote Code Execution vulnerability in P4 (Helix Core) Ser…7.7
- CVE-2026-6903The LabOne Web Server, backing the LabOne User Interface, co…8.7
Are you affected by CVE-2026-68980?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
