Apache DolphinScheduler: command injection
High8.8CVE-2026-82804 · Published Sep 29, 2026
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache DolphinScheduler Product | < 3.4.3 | 3.4.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-78
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Apache Polaris: missing authorization | High8.1 | 1.8.0 |
| Sep 29 | Apache DolphinScheduler: improper authorization | Medium4.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: missing authorization | Medium6.5 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: authentication bypass | Medium5.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: improper authorization | Medium4.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: improper authorization | Medium4.3 | 3.4.3 |