Improper Authorization Vulnerability in Apache DolphinScheduler
CVE-2026-71897

4.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-71897?

An improper authorization check in Apache DolphinScheduler enables authenticated users to exploit batch-copy and batch-move endpoints. This deficiency allows them to manipulate workflows in projects without the necessary permissions, potentially leading to unauthorized access and management of sensitive data. Users are encouraged to update to version 3.4.3, which addresses this critical issue.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
Yeonoh Park
.