Sceawere
Vulnerability Detail
CVE-2026-81569UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DolphinScheduler Improper Workflow Authorization
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 11h ago
- Vendor
- Apache Software Foundation
- Product
- Apache DolphinScheduler
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system does not properly verify whether the user has permission to execute the referenced workflow or access its project. As a result, the user can bypass project-level authorization controls and cause workflows in unauthorized projects to be executed. Successful exploitation may allow unauthorized execution of workflow tasks and access to the resources or data available to the target workflow. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-29T14:17:21.650Z",
"pubdate": "2026-09-29T14:17:21.650Z",
"executiveSummary": "An improper authorization vulnerability exists in Apache DolphinScheduler, specifically within the sub-workflow task management logic. The vulnerability permits an authenticated user to bypass project-level access controls by referencing and invoking workflows across unauthorized projects.\nThe root cause is a deficiency in the authorization verification process when handling sub-workflow task definitions. The system fails to validate whether the authenticated user possesses the requisite project permissions to execute a target sub-workflow.\nThis flaw allows a malicious actor with authenticated access to trigger unauthorized workflow executions, potentially leading to unauthorized resource access, data exposure, and manipulation of business logic within projects they are not permitted to manage. The vulnerability affects Apache DolphinScheduler versions prior to 3.4.3.\nThe risk is considered significant as it circumvents the fundamental security boundary enforced by the project-based multi-tenancy model. Successful exploitation requires an authenticated session but does not require administrative privileges on the target project.",
"technicalDetails": "The vulnerability resides within the Apache DolphinScheduler workflow orchestration engine, specifically in the sub-workflow task handling module. When a user defines a task of type 'SUB_PROCESS', the application allows the configuration of a reference to a target workflow defined in another project.\nThe exploitation occurs due to an insufficient authorization check during the validation of task definitions. When a user creates or executes a sub-workflow task, the backend logic parses the workflow definition and identifies the referenced target project/workflow. However, the system fails to verify the relationship between the authenticated user's authorization scope and the target sub-workflow's project affiliation.\nThe attack flow proceeds as follows: 1) An authenticated attacker with access to at least one project initiates the creation of a new workflow task. 2) The attacker specifies a sub-workflow task definition that points to a target workflow located within an unauthorized project. 3) Upon task execution, the controller responsible for scheduling sub-processes retrieves the target definition without validating if the current user has read or execute permissions on the destination project. 4) The orchestrator proceeds to instantiate the target workflow, thereby executing the logic within the context of the unauthorized project.\nThis authorization bypass violates the principle of least privilege, as the service implicitly trusts the sub-workflow reference provided by the user without cross-referencing it against the Access Control List (ACL) of the target project. This allows an attacker to execute workflows that may contain sensitive data processing, interact with external systems, or modify persistent data in projects to which they are not explicitly granted access.\nThe vulnerability is present in versions of Apache DolphinScheduler prior to 3.4.3. The security flaw is confined to the server-side workflow execution layer and does not require complex network interception, as it is a logic-based authorization failure inherent to the application's processing of cross-project sub-workflow references. Post-exploitation impact includes the ability to trigger unauthorized tasks, potentially leading to unauthorized data modification, information disclosure, or further compromise of workflow-integrated systems."
}