CVE-2026-78214: Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
Percent-encoded paths can bypass Actuator authentication in Apache DolphinScheduler versions before 3.4.3.
CVE-2026-78214 is an authentication-bypass flaw, rated low by Apache, in Apache DolphinScheduler API versions before 3.4.3. The application decides whether Actuator endpoints require authentication by matching the incoming request path against protected paths. A remote requester can supply a percent-encoded path so the endpoint is not recognized as protected. Active exploitation is not described.
- Affects the DolphinScheduler API before 3.4.3.
- Actuator protection depends on literal request-path matching.
- Percent-encoded paths can bypass the authentication check.
- Apache rates the vulnerability low.
Vulnerabilities mentionedAll →
- CVE-2026-782145.3—Actuator auth bypass in Apache DolphinSchedulerpublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-78214 | Actuator auth bypass in Apache DolphinScheduler Apache DolphinScheduler before 3.4.3 has an authentication bypass in how it decides whether Actuator endpoints require authentication. The check matches the incoming request path against protected Actuator paths, and a remote unauthenticated attacker can send a percent-encoded path so the request is not recognized as targeting a protected endpoint. Successful exploitation can expose operational or configuration information and, depending on which Actuator endpoints are enabled and how the application is configured, may allow access to sensitive management functionality. Anyone running an affected DolphinScheduler version with reachable Actuator endpoints is at risk. There is no known public proof of concept and no report of exploitation in the wild; the issue is not listed in CISA KEV and has not yet been scored. |
Posted by Wenjun Ruan on Sep 29 Severity: low Affected versions: - Apache DolphinScheduler (org.apache.dolphinscheduler:dolphinscheduler-api) before 3.4.3 Description: An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote...
This source does not provide full text. Read it at seclists.org.