Sceawere

Vulnerability Detail

CVE-2026-71897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DolphinScheduler Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
11h ago
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-29T14:17:20.947Z",
  "pubdate": "2026-09-29T14:17:20.947Z",
  "executiveSummary": "Apache DolphinScheduler contains an improper authorization vulnerability within its workflow management subsystem, specifically involving batch-copy and batch-move operations.\nThis flaw allows an authenticated attacker to bypass standard project-level permission checks, enabling unauthorized manipulation of workflow resources across different project scopes.\nThe vulnerability resides in the backend API endpoints responsible for bulk processing of workflow objects, which fail to adequately validate user entitlements against the source project resources.\nThe primary risk is the unauthorized movement or duplication of sensitive workflow definitions, which could lead to project data exposure, integrity loss, or the unauthorized migration of automated business logic into environments accessible to the attacker.\nExploitation requires the attacker to possess an authenticated session within the application, but it does not necessitate administrative privileges. No additional external preconditions are specified for successful exploitation.\nAffected systems include Apache DolphinScheduler versions prior to 3.4.3. Remediation requires an immediate upgrade to the patched release.",
  "technicalDetails": "The vulnerability is rooted in an insufficient authorization logic within the Apache DolphinScheduler workflow management module. Specifically, the API endpoints designated for batch-copy and batch-move operations do not perform comprehensive verification of user permissions for the source project resources during the request processing cycle.\nWhen a user invokes these batch operations, the system is expected to perform an access control list (ACL) check to ensure the requester holds sufficient read or write privileges for both the source and target project directories. In the vulnerable versions, the backend fails to validate the user's authority against the specific project IDs associated with the target workflows during the batch execution flow.\nThe attack flow proceeds as follows: 1) An authenticated user initiates a POST or relevant HTTP request to the vulnerable batch-copy or batch-move API endpoints. 2) The attacker specifies the target workflow IDs located within a project for which they lack authorized access. 3) The application’s internal controller fails to verify if the session user is a member of the project or possesses the necessary roles to manipulate these specific objects. 4) The server processes the request as if the user held the required authority, allowing the movement or duplication of workflow resources.\nThis behavior constitutes a Broken Access Control (BAC) vulnerability where the security boundary between different projects is effectively ignored. An attacker can leverage this to 'exfiltrate' workflow metadata by moving or copying them into an environment they control, effectively bypassing project-based access restrictions. Given that workflows often contain sensitive credentials, script configurations, and business logic, the impact of unauthorized access is significant.\nThe vulnerability affects Apache DolphinScheduler versions prior to 3.4.3. The root cause is likely an incomplete check of user-to-project mappings in the business logic layer that handles batch service requests, potentially due to the omission of authorization interceptors or improper validation logic within the service implementation for mass-operation endpoints. Since the exploitation occurs at the application level via authorized API calls, standard network-based firewalls would not prevent the attack if the attacker has valid credentials."
}
CVE-2026-71897: DolphinScheduler Improper Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere