Skip to content

Apache DolphinScheduler: improper authorization

Medium4.3CVE-2026-71898 · Published Sep 29, 2026

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache DolphinScheduler
Product
< 3.4.33.4.3
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Polaris: missing authorization
High8.1Sep 29
Apache DolphinScheduler: missing authorization
Medium6.5Sep 29
Apache DolphinScheduler: authentication bypass
Medium5.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: command injection
High8.8Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.