CVE-2026-71897: Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
DolphinScheduler before 3.4.3 lets authenticated users copy or move workflows they are not permitted to access.
Apache DolphinScheduler before 3.4.3 has an improper authorization check on the batch-copy and batch-move endpoints. An authenticated user can copy or move workflows in projects where they lack the required permissions. Apache rates the issue moderate. No exploitation in the wild is reported.
- Affects Apache DolphinScheduler versions before 3.4.3.
- Authenticated users can batch-copy or batch-move workflows without project permission.
- Apache rates the improper authorization issue as moderate.
- Impact is copying or moving workflows from unauthorized projects.
Vulnerabilities mentionedAll →
- CVE-2026-718974.3—Incorrect authorization in Apache DolphinScheduler workflow batch opspublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71897 | Incorrect authorization in Apache DolphinScheduler workflow batch ops Apache DolphinScheduler before 3.4.3 has an incorrect authorization check (CWE-863) on its batch-copy and batch-move workflow endpoints. An already authenticated user can call those endpoints to copy or move workflows that belong to projects they are not permitted to access. Impact is unauthorized workflow relocation or duplication across projects, not unauthenticated remote code execution. Only deployments running a release older than 3.4.3 are affected. The issue is not listed in CISA KEV, has no known public proof-of-concept, and is not known to be exploited in the wild; CVSS has not yet been scored. Do: Upgrade Apache DolphinScheduler to 3.4.3 or later. Until then, restrict which authenticated users can reach the batch-copy and batch-move workflow APIs, and review audit logs for copies or moves of workflows across projects the actor was not permitted to access. |
Posted by Wenjun Ruan on Sep 29 Severity: moderate Affected versions: - Apache DolphinScheduler before 3.4.3 Description: An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects Apache DolphinScheduler: before 3.4.3....
This source does not provide full text. Read it at seclists.org.