CVE-2026-82804
Received Received - Intake

Command Injection in Apache DolphinScheduler

Vulnerability report for CVE-2026-82804, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache dolphinscheduler to 3.4.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper handling of the scriptPath parameter in a shell command. The parameter is used in a /bin/sh -c command without proper sanitization of shell metacharacters. An attacker can inject commands using syntax like $(...) to execute arbitrary commands with the privileges of the DolphinScheduler service process.

Detection Guidance

Check Apache DolphinScheduler versions before 3.4.3. Inspect logs for unusual scriptPath values containing $(...) or similar shell metacharacters. Search for command execution patterns in alert script logs.

Impact Analysis

An authenticated user can exploit this to execute arbitrary commands on the system running DolphinScheduler. This could lead to unauthorized access, data theft, or system compromise, depending on the privileges of the service process.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements such as GDPR or HIPAA. Organizations using vulnerable versions of DolphinScheduler may face regulatory penalties or legal consequences if exploited.

Mitigation Strategies

Upgrade Apache DolphinScheduler to version 3.4.3 or later immediately. If upgrading is not possible, restrict access to the /test-send endpoint and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82804. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart