CVE Explorer
CVE-2026-68980
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement differen
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageName":"org.apache.nifi:nifi-web-api","product":"Apache NiFi","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.10.0","status":"affected","version":"2.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a935fd1cbc0b95ac1b323f865b749eb6e9262e51f059c02eb381c7b5aab63bee · sha256:80b89d7e022f7e01… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"YES","Recovery":"USER","Safety":"NEGLIGIBLE","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":2.3,"baseSeverity":"LOW","privilegesRequired":"LOW","providerUrgency":"CLEAR","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:L/U:Clear","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpa…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a935fd1cbc0b95ac1b323f865b749eb6e9262e51f059c02eb381c7b5aab63bee · sha256:80b89d7e022f7e01… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863 Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a935fd1cbc0b95ac1b323f865b749eb6e9262e51f059c02eb381c7b5aab63bee · sha256:80b89d7e022f7e01… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/08/03/12"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a935fd1cbc0b95ac1b323f865b749eb6e9262e51f059c02eb381c7b5aab63bee · sha256:80b89d7e022f7e01… · /containers/adp/0/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/yo8k6tt3zxjm49zzhly3453v0xhwm3o1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a935fd1cbc0b95ac1b323f865b749eb6e9262e51f059c02eb381c7b5aab63bee · sha256:80b89d7e022f7e01… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.