---
id: CVE-2026-71897
title: >-
  An improper authorization check in Apache DolphinScheduler allows an
  authenticated user to use the batch-copy and batch-move endpoints to operate
  on workflows in projects for which they lack the required permissions
summary: >-
  An improper authorization check in Apache DolphinScheduler allows an
  authenticated user to use the batch-copy and batch-move endpoints to operate
  on workflows in projects for which they lack the required permissions. This
  may allow the u…
severity: none
cwe:
  - CWE-863
vendor: Apache Software Foundation
product: 'org.apache.dolphinscheduler:dolphinscheduler-api'
affected:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.3'
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:17:20.947'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71897'
references:
  - url: 'https://lists.apache.org/thread.html/ksnowtbpd9t4mbtvvq2c9777j42784dv'
    label: security@apache.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T13:34:31.683Z'
---

## Overview

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
