CVE-2026-71898: Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache DolphinSchedulerto a version that resolves this vulnerability.Fixed in 3.4.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and have read permission for the affected project. No write permission is required to modify a workflow instance through the vulnerable endpoint.
Which deployments are affected?
Apache DolphinScheduler versions before 3.4.3 are affected. Projects where users are granted read-only access are exposed because those users can send PUT requests to the workflow-instance endpoint.
What can a read-only project user do through the vulnerable endpoint?
They can modify a workflow instance in the project via PUT /projects/{projectCode}/workflow-instances/{id}. This permits unauthorized changes to workflow instances and workflow definitions.
What is the recommended remediation?
Upgrade Apache DolphinScheduler to version 3.4.3, which fixes the authorization check.