freenode
Security & Cryptography

Apache NiFi auth flaw let read-only users override parameter checks

CVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.

Apache NiFi 1.10.0 through 2.10.0 mishandled authorization on Parameter Context validation requests, a high-severity flaw tracked as CVE-2026-62354. Clients with only read access could submit proposed parameter values that overrode the current configuration and ran predefined component validation methods under those alternate settings.

Installations that do not separate view and modify rights for Parameter Context configuration were not exposed. The recommended fix is to upgrade to Apache NiFi 2.11.0, which requires write access before accepting such validation requests.

Nguyen Van Hiep of MBBank reported the issue. It is tracked upstream as NIFI-16112.