CVE-2026-71898: Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions
CVE-2026-71898 lets DolphinScheduler read-only users modify workflows through a missing authorization check.
Apache DolphinScheduler versions before 3.4.3 are affected by CVE-2026-71898, an incorrect authorization check rated moderate. An authenticated user with only read permission on a project can modify a workflow instance through PUT /projects/{projectCode}/workflow-instances/{id} because the endpoint does not enforce the required write permission. The disclosure says this can allow the user to execute workflows and tamper with workflow definitions. No exploitation in the wild is reported.
- CVE-2026-71898 affects Apache DolphinScheduler before version 3.4.3.
- Authenticated project read-only users can call a workflow-instance PUT endpoint.
- The missing write-permission check can allow workflow modification and execution.
- The issue is rated moderate, with no in-the-wild exploitation reported.
Vulnerabilities mentionedAll →
- CVE-2026-718984.3—Incorrect authorization in Apache DolphinSchedulerpublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71898 | Incorrect authorization in Apache DolphinScheduler Apache DolphinScheduler before 3.4.3 has an incorrect authorization check (CWE-863) on PUT /projects/{projectCode}/workflow-instances/{id}. An authenticated user who has only read permission on a project can call that endpoint and modify a workflow instance, because the handler does not require the write permission this operation needs. The result is unauthorized changes to workflow instances by accounts that should be limited to read access. Any installation of Apache DolphinScheduler older than 3.4.3 is affected. No public proof of concept is known and the issue is not in CISA KEV, so exploitation is none known. Do: Upgrade Apache DolphinScheduler to 3.4.3 or later, which enforces the required write permission on this endpoint. Until then, do not grant project access to users who must not change workflows, and review workflow-instance history for unexpected edits by read-only accounts. |
Posted by Wenjun Ruan on Sep 29 Severity: moderate Affected versions: - Apache DolphinScheduler before 3.4.3 Description: An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to...
This source does not provide full text. Read it at seclists.org.