Apache Software FoundationCVE-2026-71898
Apache DolphinScheduler: improper authorization
Medium4.3CVE-2026-71898 · Published Sep 29, 2026
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache DolphinScheduler Product | < 3.4.3 | 3.4.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-863
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Apache Polaris: missing authorization | High8.1 | 1.8.0 |
| Sep 29 | Apache DolphinScheduler: missing authorization | Medium6.5 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: authentication bypass | Medium5.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: improper authorization | Medium4.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: improper authorization | Medium4.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: command injection | High8.8 | 3.4.3 |