Sceawere
Vulnerability Detail
CVE-2026-71898UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DolphinScheduler Broken Access Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 11h ago
- Vendor
- Apache Software Foundation
- Product
- Apache DolphinScheduler
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-29T14:17:21.067Z",
"pubdate": "2026-09-29T14:17:21.067Z",
"executiveSummary": "A broken access control vulnerability exists in Apache DolphinScheduler, stemming from an incorrect authorization check within the project workflow management module.\nThe vulnerability allows an authenticated user, assigned only read-level permissions, to perform unauthorized write operations on workflow instances.\nBy targeting the PUT /projects/{projectCode}/workflow-instances/{id} endpoint, an attacker can modify sensitive workflow configurations despite lacking the requisite administrative or write privileges.\nThis flaw impacts Apache DolphinScheduler versions prior to 3.4.3, posing a significant risk to data integrity and workflow orchestration security.\nThe vulnerability requires the attacker to possess a valid, albeit restricted, user account within the platform.\nExploitation results in unauthorized state modification, potentially allowing malicious actors to alter execution logic, disrupt operational pipelines, or manipulate resource allocation within the Apache DolphinScheduler environment.",
"technicalDetails": "The root cause of this vulnerability is an improper implementation of authorization logic within the application's API layer, specifically regarding the handling of permission validation for workflow instance management.\nThe application fails to perform a comprehensive Role-Based Access Control (RBAC) check at the controller level for the PUT /projects/{projectCode}/workflow-instances/{id} endpoint.\nUnder normal security design, this endpoint should trigger an interceptor or service-layer validation to verify that the requesting user's session token carries 'write' or 'owner' project-level permissions.\nInstead, the system incorrectly validates the request based solely on the presence of an active authentication session, bypassing the necessity for higher-level authorization.\nAttack flow begins with an authenticated attacker possessing 'read-only' project access. The attacker identifies a target workflow instance ID within the authorized project scope.\nThe attacker initiates a malicious HTTP PUT request to the aforementioned endpoint, appending modified parameters to the request body representing the intended changes to the workflow instance.\nUpon receiving the request, the vulnerable backend service processes the update without confirming the user's write authorization status against the provided {projectCode}.\nThis failure allows the modification of workflow instance metadata or execution parameters. Since the system trusts the request provenance solely on session validity, the modification is committed to the underlying database.\nAffected components include the REST API controller responsible for workflow instance updates. The vulnerability is present in all versions of Apache DolphinScheduler preceding version 3.4.3.\nSuccessful exploitation allows for post-exploitation impacts such as workflow manipulation, potentially leading to unauthorized task execution, denial-of-service through resource exhaustion, or the subversion of automated data pipelines managed by DolphinScheduler.\nThe network exposure is restricted to the management interface, but the impact is critical given the elevated role these workflows often play in organizational data infrastructure."
}