CVE-2026-71898None▾ SunlitAn incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78214NoneAn authentication bypass vulnerability exists in the protection of Actuator endpoints
CVE-2026-71899NoneA missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler
CVE-2026-71897NoneAn improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions
CVE-2026-57590High· 8.1A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler
CVE-2026-32966Critical· 9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVE-2026-32967Critical· 9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks