Missing Authorization Vulnerability in Apache DolphinScheduler API
CVE-2026-71899

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-71899?

A missing authorization vulnerability is present in the query-dynamic-sub-workflows API of Apache DolphinScheduler, which fails to correctly verify if an authenticated user has the necessary permissions to access specific workflows. This oversight allows users to invoke the API with parameters that reference workflows belonging to projects they are not authorized to access, leading to unauthorized information disclosure. As a result, sensitive workflow data can be retrieved outside the user's authorized project scope. To mitigate this issue, users are strongly advised to upgrade to version 3.4.3 of Apache DolphinScheduler.

Affected Version(s)

Apache DolphinScheduler 3.2.0 < 3.4.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yansong
MopMonk AI
.