CVE-2026-71899: Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure
Apache DolphinScheduler's query-dynamic-sub-workflows API fails to check project permissions, letting authenticated users view unauthorized workflow data before version 3.4.3.
CVE-2026-71899 is a missing authorization flaw rated low severity in Apache DolphinScheduler 3.2.0 through versions before 3.4.3. The query-dynamic-sub-workflows API does not verify whether the authenticated user has permission to access the queried workflows, allowing users outside a project to retrieve workflow information. The issue is resolved in DolphinScheduler 3.4.3.
- Missing authorization in query-dynamic-sub-workflows API
- Affects DolphinScheduler 3.2.0 before 3.4.3, rated low severity
- Authenticated users can access workflows in projects they cannot access
- Fixed in version 3.4.3
Vulnerabilities mentionedAll →
- CVE-2026-718996.5—Missing authorization in Apache DolphinScheduler workflow APIpublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71899 | Missing authorization in Apache DolphinScheduler workflow API Apache DolphinScheduler versions from 3.2.0 before 3.4.3 have a missing authorization flaw (CWE-863) in the query-dynamic-sub-workflows API. An authenticated user who lacks access to a given project can call the API with parameters that reference that project’s workflows and receive workflow information they are not allowed to see. The result is unauthorized disclosure of workflow data across project boundaries, not remote code execution. Organizations running affected DolphinScheduler releases are impacted. There is no known public proof of concept and the issue is not listed in CISA KEV. Do: Upgrade Apache DolphinScheduler to 3.4.3 or later, which fixes the missing authorization check. Until then, restrict access to the query-dynamic-sub-workflows API (network controls and least-privilege project roles) and review API logs for authenticated users querying workflow IDs outside their assigned projects. |
Posted by Wenjun Ruan on Sep 29 Severity: low Affected versions: - Apache DolphinScheduler 3.2.0 before 3.4.3 Description: A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can invoke the API with parameters...
This source does not provide full text. Read it at seclists.org.