Sceawere

Vulnerability Detail

CVE-2026-71898UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DolphinScheduler Broken Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
11h ago
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-29T14:17:21.067Z",
  "pubdate": "2026-09-29T14:17:21.067Z",
  "executiveSummary": "A broken access control vulnerability exists in Apache DolphinScheduler, stemming from an incorrect authorization check within the project workflow management module.\nThe vulnerability allows an authenticated user, assigned only read-level permissions, to perform unauthorized write operations on workflow instances.\nBy targeting the PUT /projects/{projectCode}/workflow-instances/{id} endpoint, an attacker can modify sensitive workflow configurations despite lacking the requisite administrative or write privileges.\nThis flaw impacts Apache DolphinScheduler versions prior to 3.4.3, posing a significant risk to data integrity and workflow orchestration security.\nThe vulnerability requires the attacker to possess a valid, albeit restricted, user account within the platform.\nExploitation results in unauthorized state modification, potentially allowing malicious actors to alter execution logic, disrupt operational pipelines, or manipulate resource allocation within the Apache DolphinScheduler environment.",
  "technicalDetails": "The root cause of this vulnerability is an improper implementation of authorization logic within the application's API layer, specifically regarding the handling of permission validation for workflow instance management.\nThe application fails to perform a comprehensive Role-Based Access Control (RBAC) check at the controller level for the PUT /projects/{projectCode}/workflow-instances/{id} endpoint.\nUnder normal security design, this endpoint should trigger an interceptor or service-layer validation to verify that the requesting user's session token carries 'write' or 'owner' project-level permissions.\nInstead, the system incorrectly validates the request based solely on the presence of an active authentication session, bypassing the necessity for higher-level authorization.\nAttack flow begins with an authenticated attacker possessing 'read-only' project access. The attacker identifies a target workflow instance ID within the authorized project scope.\nThe attacker initiates a malicious HTTP PUT request to the aforementioned endpoint, appending modified parameters to the request body representing the intended changes to the workflow instance.\nUpon receiving the request, the vulnerable backend service processes the update without confirming the user's write authorization status against the provided {projectCode}.\nThis failure allows the modification of workflow instance metadata or execution parameters. Since the system trusts the request provenance solely on session validity, the modification is committed to the underlying database.\nAffected components include the REST API controller responsible for workflow instance updates. The vulnerability is present in all versions of Apache DolphinScheduler preceding version 3.4.3.\nSuccessful exploitation allows for post-exploitation impacts such as workflow manipulation, potentially leading to unauthorized task execution, denial-of-service through resource exhaustion, or the subversion of automated data pipelines managed by DolphinScheduler.\nThe network exposure is restricted to the management interface, but the impact is critical given the elevated role these workflows often play in organizational data infrastructure."
}
CVE-2026-71898: DolphinScheduler Broken Access Control (MEDIUM Severity, CVSS: 4.3) | Sceawere