Skip to content

Apache DolphinScheduler: missing authorization

Medium6.5CVE-2026-71899 · Published Sep 29, 2026 · updated Oct 1, 2026

A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can invoke the API with parameters referencing workflows belonging to that project and retrieve workflow information. This allows users to access workflow data outside their authorized project scope, resulting in unauthorized information disclosure. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache DolphinScheduler
Product
>= 3.2.0, < 3.4.33.4.3
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Polaris: missing authorization
High8.1Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: authentication bypass
Medium5.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: command injection
High8.8Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.