MEDIUM 4.3 NVD
CVE-2026-71898
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance i
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
References
- https://lists.apache.org/thread/lt35p8xc1w7ovgq68g4zz1c8vnk5ow6o
- http://www.openwall.com/lists/oss-security/2026/09/29/21
- https://www.openwall.com/lists/oss-security/2026/09/29/21
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.