Sceawere

Vulnerability Detail

CVE-2026-78214UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DolphinScheduler Actuator Authentication Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated attacker can cause the security check to fail to recognize the request as targeting a protected endpoint. As a result, the attacker may bypass authentication and access otherwise restricted Actuator endpoints. Successful exploitation may expose operational or configuration information and, depending on the enabled endpoints and application configuration, allow access to sensitive management functionality. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-29T14:17:21.530Z",
  "pubdate": "2026-09-29T14:17:21.530Z",
  "executiveSummary": "An authentication bypass vulnerability has been identified in Apache DolphinScheduler involving the improper protection of Actuator endpoints. The vulnerability stems from a path-matching inconsistency in the security configuration, where the application fails to correctly resolve percent-encoded characters when determining if a request path requires authentication.\nBy manipulating the request path with percent-encoding, a remote, unauthenticated attacker can effectively mask the target endpoint, causing the security filter to bypass authorization checks. This allows unauthorized access to sensitive Actuator endpoints that are intended for administrative use only.\nThe impact of this vulnerability is significant, as successful exploitation may lead to the exposure of internal operational metrics, configuration details, and potentially sensitive management functionality. Depending on the specific configuration and enabled endpoints, this may facilitate further system compromise or unauthorized information disclosure.\nThe vulnerability affects Apache DolphinScheduler versions prior to 3.4.3. Users are advised to upgrade to the patched version as the primary remediation step to restore robust access control over management interfaces.",
  "technicalDetails": "The root cause of this vulnerability lies in the security framework's path-matching logic used to identify requests targeting restricted Actuator endpoints. The application employs a filter or interceptor that performs a direct string comparison or pattern matching against the incoming request URI to enforce authentication requirements.\nThe vulnerability is triggered by a discrepancies in how the security middleware and the underlying web container handle URL decoding. When an attacker sends a request with a percent-encoded path (e.g., using double encoding or specific URL-encoded sequences), the security check layer fails to normalize the path correctly before performing the matching operation. Because the normalized path is not consistent between the security check logic and the final handler, the request fails to match against the list of protected paths.\nExploitation follows a specific flow: 1) The attacker identifies a target Actuator endpoint (e.g., /actuator/env or /actuator/heapdump). 2) The attacker crafts a request by percent-encoding portions of the URI path. 3) Upon reaching the application, the security filter evaluates the path; due to the failure in normalization, the security check concludes the path does not match the protected patterns and erroneously permits the request to proceed without authentication. 4) The web container subsequently decodes the URI and routes the request to the target Actuator endpoint, which then executes its intended function for the unauthenticated user.\nThis vulnerability effectively renders the authentication barrier for Actuator endpoints transparent to any remote attacker. The exposure of these endpoints is dangerous because Actuator endpoints often provide deep introspection into the Java Virtual Machine, environment variables, system properties, and internal configuration states. In many deployments, these endpoints may also expose endpoints capable of state modification or diagnostic collection, which significantly lowers the barrier for attackers to gain a foothold or extract sensitive credentials from the application environment.\nThe affected component is the security configuration responsible for mapping URL patterns to authorization requirements. All Apache DolphinScheduler deployments prior to version 3.4.3 are inherently vulnerable. No specific privileges or prior authentication are required to execute this attack, as the flaw resides in the entry-point verification mechanism itself, making it highly accessible to remote actors."
}
CVE-2026-78214: DolphinScheduler Actuator Authentication Bypass (MEDIUM Severity, CVSS: 5.3) | Sceawere