CVE-2026-71897
Received Received - Intake

Improper Authorization in Apache DolphinScheduler Allows Workflow Manipulation

Vulnerability report for CVE-2026-71897, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache dolphinscheduler to 3.4.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authorization check in Apache DolphinScheduler. An authenticated user can exploit batch-copy and batch-move endpoints to operate on workflows in projects where they do not have permission. This allows unauthorized access to workflows from restricted projects.

Detection Guidance

This vulnerability can be detected by checking Apache DolphinScheduler versions before 3.4.3. Use commands like 'curl -s http://<server>:<port>/dolphinscheduler/version' or check the installed package version via 'dpkg -l | grep dolphinscheduler' or 'rpm -qa | grep dolphinscheduler'. If the version is below 3.4.3, the system is vulnerable.

Impact Analysis

If you use Apache DolphinScheduler before version 3.4.3, an attacker with valid credentials could access or manipulate workflows in projects they are not authorized to view or modify. This could lead to data leaks, workflow disruption, or unauthorized changes to critical processes.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by allowing unauthorized access to sensitive workflows or data. It may lead to data breaches, unauthorized processing, or failure to maintain proper access controls, resulting in legal and regulatory penalties.

Mitigation Strategies

Upgrade Apache DolphinScheduler to version 3.4.3 or later to fix the improper authorization check vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71897. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart