securityonline.info 8/4/2026, 3:21:16 AM · external

Apache NiFi flaws enable code execution and auth bypass

Apache NiFi flaws enable code execution and auth bypass
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

FOUR new vulnerabilities in Apache NiFi (versions prior to 2.11.0) allow code execution, authorization bypass, and system resource consumption. Users are urged to update to version 2.11.0 to protect their data pipelines. Key vulnerabilities include CVE-2026-68981 (8.8 severity), causing uncontrolled resource consumption, and CVE-2026-62354, which allows incorrect authorization for validation requests.

No exploits have been confirmed yet, but these flaws could significantly impact operations and expose sensitive information. Immediate action is recommended to secure installations.

View full article

Article by CyberSIXT