Authorization Flaw in Apache DolphinScheduler Affects User Workflow Control
CVE-2026-71898
4.3MEDIUM
What is CVE-2026-71898?
An authorization vulnerability in Apache DolphinScheduler allows authenticated users with only read permissions to modify workflow instances within a project. Specifically, the PUT /projects/{projectCode}/workflow-instances/{id} endpoint fails to enforce write permissions, resulting in unauthorized modifications. This issue underscores the importance of properly enforcing user permissions to prevent unauthorized access and alterations in project workflows. Users should upgrade to version 3.4.3 or later to mitigate this risk.
Affected Version(s)
Apache DolphinScheduler 0 < 3.4.3