MEDIUM 4.3 NVD
CVE-2026-71897
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows i
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
References
- https://lists.apache.org/thread.html/ksnowtbpd9t4mbtvvq2c9777j42784dv
- http://www.openwall.com/lists/oss-security/2026/09/29/20
- https://www.openwall.com/lists/oss-security/2026/09/29/20
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.