CVE-2026-71899
Received Received - Intake

Missing Authorization in Apache DolphinScheduler Workflow Query API

Vulnerability report for CVE-2026-71899, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can invoke the API with parameters referencing workflows belonging to that project and retrieve workflow information. This allows users to access workflow data outside their authorized project scope, resulting in unauthorized information disclosure. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache dolphinscheduler From 3.2.0 (inc) to 3.4.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a missing authorization vulnerability in Apache DolphinScheduler's `query-dynamic-sub-workflows` API. The API fails to verify if an authenticated user has permission to access the workflows they are querying. As a result, users without proper access can retrieve workflow data from projects they are not authorized to view, leading to unauthorized information disclosure.

Detection Guidance

To detect this vulnerability, check Apache DolphinScheduler logs for unauthorized API calls to the query-dynamic-sub-workflows endpoint. Look for requests with project-specific workflow parameters from users without proper permissions. Verify if workflow data outside their authorized scope is being accessed.

Impact Analysis

If you are an Apache DolphinScheduler user running versions 3.2.0 to 3.4.2, an attacker with valid credentials but limited permissions could exploit this flaw to access sensitive workflow data from restricted projects. This could lead to data leaks, unauthorized modifications, or further exploitation within your system.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by allowing unauthorized access to sensitive data. GDPR mandates strict data access controls, while HIPAA requires safeguards for protected health information. Exploiting this flaw may result in unauthorized data exposure, leading to legal penalties or reputational damage.

Mitigation Strategies

Upgrade Apache DolphinScheduler to version 3.4.3 or later to fix the missing authorization vulnerability in the query-dynamic-sub-workflows API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71899. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart