Authorization Flaw in Apache DolphinScheduler Affects User Workflow Control
CVE-2026-71898

4.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-71898?

An authorization vulnerability in Apache DolphinScheduler allows authenticated users with only read permissions to modify workflow instances within a project. Specifically, the PUT /projects/{projectCode}/workflow-instances/{id} endpoint fails to enforce write permissions, resulting in unauthorized modifications. This issue underscores the importance of properly enforcing user permissions to prevent unauthorized access and alterations in project workflows. Users should upgrade to version 3.4.3 or later to mitigate this risk.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dipak Panchal
.