Apache DolphinScheduler 3.4.3 security batch: seven CVEs spanning authorization flaws, an Actuator authentication bypass, and Alert Script command injection
Seven CVEs disclosed on 2026-09-29 affect Apache DolphinScheduler before 3.4.3: five improper- or missing-authorization flaws that let authenticated users read data-source details and copy, move, modify, or execute workflows in unauthorized projects, plus an…
Seven oss-security advisories published between 13:25 and 13:38 UTC on 2026-09-29 describe vulnerabilities in Apache DolphinScheduler, all affecting versions before 3.4.3. Five are authorization flaws exploitable by authenticated users: CVE-2026-66083 (moderate) leaks data-source configuration and sensitive metadata through the /datasources/unauth-datasource endpoint, which skips authorization checks; CVE-2026-71897 (moderate) allows users to batch-copy or batch-move workflows from projects where they lack permission; CVE-2026-71898 (moderate) lets project read-only users execute workflows and tamper with workflow definitions via PUT /projects/{projectCode}/workflow-instances/{id} because the endpoint does not enforce write permission; CVE-2026-71899 (low) lets users outside a project retrieve workflow information through the query-dynamic-sub-workflows API (specifically affecting 3.2.0 through versions before 3.4.3 and fixed in 3.4.3); and CVE-2026-81569 (moderate) allows an authenticated user to reference and invoke a workflow in a project they cannot access through a sub-workflow task. Two advisories break the pattern: CVE-2026-78214 (low), scoped to the DolphinScheduler API, is an authentication bypass in which a remote requester can supply a percent-encoded path so an Actuator endpoint is not recognized as protected, because protection relies on literal request-path matching; and CVE-2026-82804 (low), disclosed by Wenjun Ruan, is command injection in the Alert Script plugin, where the scriptPath parameter is incorporated into a /bin/sh -c command without neutralizing shell metacharacters, allowing an authenticated user to trigger command substitution through a crafted resource filename. None of the advisories report exploitation in the wild.
- All seven CVEs (CVE-2026-66083, CVE-2026-71897, CVE-2026-71898, CVE-2026-71899, CVE-2026-78214, CVE-2026-81569, CVE-2026-82804) affect Apache DolphinScheduler before version 3.4.3; the fix version 3.4.3 is explicitly stated only for…
- CVE-2026-66083 (moderate): the /datasources/unauth-datasource endpoint skips authorization, letting authenticated users read configuration and sensitive metadata for data sources they are not allowed to access.
- CVE-2026-71897 (moderate): improper authorization on the batch-copy and batch-move endpoints lets authenticated users copy or move workflows in projects where they lack the required permissions.
Coverage timelineoldest first · each row is one article
- · 9d agoCVE-2026-66083: Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
oss-security· 43
DolphinScheduler before 3.4.3 can leak unauthorized data-source configuration and metadata to authenticated users.
- · 9d agoCVE-2026-71897: Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
oss-security· 41
DolphinScheduler before 3.4.3 lets authenticated users copy or move workflows they are not permitted to access.
- · 9d ago
Vulnerabilities in this storyAll →
- CVE-2026-828048.8—Authenticated Command Injection in Apache DolphinScheduler Alert Script Pluginpublished · Apache DolphinScheduler+4 related
- CVE-2026-782145.3—Actuator auth bypass in Apache DolphinSchedulerpublished · Apache DolphinScheduler+1 related