Executive brief
Apache NiFi's REST API for managing assets linked to Parameter Contexts fails to properly verify ownership before allowing asset deletion. An attacker with API access can delete assets belonging to Parameter Contexts they don't have permission to modify, potentially disrupting workflow configuration and data pipeline operations. This vulnerability only affects deployments that use different authorization levels across Parameter Contexts.
Technical details
The vulnerability is an authorization bypass in NiFi's Parameter Context Asset deletion endpoint. The REST API performs authorization checks against the supplied Parameter Context Identifier without verifying that the requested Asset actually belongs to that Parameter Context. An authenticated attacker can manipulate the Parameter Context Identifier to delete assets from contexts they don't have write permissions for. The fix, available in Apache NiFi 2.11.0, adds ownership verification matching the strategy used for Asset read operations. The vulnerability requires REST API access but does not affect installations using uniform authorization across all Parameter Contexts, as the framework's write permission enforcement acts as a secondary boundary.
Affected products
- Apache NiFi 2.0.0 through 2.10.0
Timeline
- 2026-08-03: disclosed: CVE-2026-68980 published
- 2026: patched: Fix available in Apache NiFi 2.11.0
- 2026-07-27: other: Vulnerability reported by mak3bread (Minseong Kim)