Authentication Bypass Vulnerability in Apache DolphinScheduler
CVE-2026-78214
5.3MEDIUM
What is CVE-2026-78214?
An authentication bypass vulnerability is present in the protection mechanism for Actuator endpoints of Apache DolphinScheduler. This vulnerability allows a remote unauthenticated attacker to exploit specially crafted requests that manipulate the incoming request path, evading the security checks intended to protect restricted endpoints. Consequently, attackers can gain unauthorized access to sensitive operational or configuration information and management functionalities within the application. Users are urged to upgrade their instance to version 3.4.3 or later to mitigate this vulnerability effectively.
Affected Version(s)
Apache DolphinScheduler 0 < 3.4.3