Missing Authorization Vulnerability in Apache DolphinScheduler API
CVE-2026-71899
Currently unrated
What is CVE-2026-71899?
A missing authorization vulnerability is present in the query-dynamic-sub-workflows API of Apache DolphinScheduler, which fails to correctly verify if an authenticated user has the necessary permissions to access specific workflows. This oversight allows users to invoke the API with parameters that reference workflows belonging to projects they are not authorized to access, leading to unauthorized information disclosure. As a result, sensitive workflow data can be retrieved outside the user's authorized project scope. To mitigate this issue, users are strongly advised to upgrade to version 3.4.3 of Apache DolphinScheduler.
Affected Version(s)
Apache DolphinScheduler 3.2.0 < 3.4.3