https://seclists.org/oss-sec/2026/q3/396: CVE-2026-68979: Apache NiFi: Missing Authorization for Components fenced by Parameter Context Updates
Published Aug 3, 2026
·Updated
Affected Software
1 affected component
Apache nifi>=1.10.0<=2.10.0
Frequently Asked Questions
1
What is the severity of CVE-2026-68979?
The severity of CVE-2026-68979 is classified as Medium.
2
Which versions of Apache NiFi are affected by CVE-2026-68979?
CVE-2026-68979 affects Apache NiFi versions 1.10.0 through 2.10.0.
3
How do I fix CVE-2026-68979?
To fix CVE-2026-68979, update to the latest version of Apache NiFi that includes the authorization enforcement patch.
4
What type of vulnerability is CVE-2026-68979?
CVE-2026-68979 is a missing authorization vulnerability that affects components referencing Parameter values.
5
What impact does CVE-2026-68979 have on Apache NiFi?
CVE-2026-68979 could allow unauthorized access to update Parameter Contexts, potentially compromising data integrity.