CVE-2026-81569: Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution
DolphinScheduler before 3.4.3 lets authenticated users execute workflows in projects they are not allowed to access.
CVE-2026-81569 is a moderate improper-authorization vulnerability in Apache DolphinScheduler API components before 3.4.3. An authenticated user who lacks permission for a target project can reference and invoke a workflow in that project through a sub-workflow task. The application does not properly verify the caller's authorization for the referenced project. No exploitation in the wild is reported.
- Affects the DolphinScheduler API before 3.4.3.
- Authenticated users can invoke workflows in unauthorized projects.
- The flaw is in sub-workflow task authorization checks.
- Apache rates the issue moderate.
Vulnerabilities mentionedAll →
- CVE-2026-815694.3—Improper authorization in Apache DolphinScheduler sub-workflowspublished · Apache Software Foundation Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81569 | Improper authorization in Apache DolphinScheduler sub-workflows Apache DolphinScheduler before 3.4.3 has an improper authorization flaw in how sub-workflow tasks are handled. An authenticated user who lacks access to a target project can still reference and invoke a workflow in that project through a sub-workflow task, because the system does not check permission to execute the referenced workflow or to access its project. Successful exploitation bypasses project-level controls and can run unauthorized workflow tasks and reach resources or data available to the target workflow. Any deployment still on a version before 3.4.3 is affected. There is no known public proof of concept, the issue is not listed in CISA KEV, and exploitation in the wild is not known. |
Posted by Wenjun Ruan on Sep 29 Severity: moderate Affected versions: - Apache DolphinScheduler (org.apache.dolphinscheduler:dolphinscheduler-api) before 3.4.3 Description: An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system does not properly verify whether...
This source does not provide full text. Read it at seclists.org.