CVE-2026-82804: Apache DolphinScheduler: Command Injection in the Alert Script Plugin
Authenticated users can inject shell commands in Apache DolphinScheduler before 3.4.3 through the Alert Script plugin.
Wenjun Ruan disclosed CVE-2026-82804, rated low by Apache, in Apache DolphinScheduler before 3.4.3. The Alert Script plugin incorporates the scriptPath parameter into a /bin/sh -c command without neutralizing shell metacharacters. An authenticated user can create a resource whose filename contains command-substitution syntax such as $(...) and cause the shell to execute it. No in-the-wild exploitation is reported.
- Affects Apache DolphinScheduler before 3.4.3.
- Alert scriptPath is passed into a /bin/sh -c command.
- Filenames containing $(...) can trigger command substitution.
- Exploitation requires an authenticated user; none is reported.
Vulnerabilities mentionedAll →
- CVE-2026-828048.8—Authenticated Command Injection in Apache DolphinScheduler Alert Script Pluginpublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82804 | Authenticated Command Injection in Apache DolphinScheduler Alert Script Plugin Apache DolphinScheduler versions before 3.4.3 contain an OS command injection flaw (CWE-78) in the Alert Script plugin: the scriptPath parameter is passed into a /bin/sh -c command without adequate neutralization of shell metacharacters. An authenticated attacker can trigger it by creating a resource whose filename contains shell command substitution syntax, such as $(...), and then supplying that path to the Alert Script plugin's /test-send endpoint, causing the injected command to execute when the alert script runs. Successful exploitation yields arbitrary command execution with the privileges of the DolphinScheduler service process. All deployments of Apache DolphinScheduler before 3.4.3 are affected, and users are advised to upgrade to 3.4.3. There is no known public proof of concept and no evidence of in-the-wild exploitation at this time. |
Posted by Wenjun Ruan on Sep 29 Severity: low Affected versions: - Apache DolphinScheduler before 3.4.3 Description: The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the...
This source does not provide full text. Read it at seclists.org.