CVE-2026-62354 Details
Description
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.
A vulnerability in Apache NiFi versions 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values for validation requests. These values can override existing configurations, enabling users to invoke component validation methods with modified settings. This issue arises in installations that lack proper authorization controls for viewing and editing Parameter Context configurations. The recommended mitigation is to upgrade to Apache NiFi 2.11.0, which requires write access to submit Parameter Context validation requests.
Users are advised to upgrade to Apache NiFi 2.11.0, which addresses this vulnerability by requiring write access for submitting Parameter Context validation requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/08/03/11 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/l17xcnnf1rm7qljmypyjxmh62cx4o4wj | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache nifi | >= 1.10.0, < 2.11.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | CVE Modified | CVE |
| Aug 3, 2026 | New CVE Received | [email protected] |