https://seclists.org/oss-sec/2026/q3/993: CVE-2026-71897: Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
Affected Software
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated Apache DolphinScheduler user. The flaw lets that user invoke batch-copy or batch-move operations on workflows in projects where they do not have the required permissions.
Which deployments are affected?
Apache DolphinScheduler versions before 3.4.3 are affected. The provided information does not identify any configuration prerequisite beyond having authenticated users able to access the affected endpoints.
What should teams do to remediate the issue?
Upgrade Apache DolphinScheduler to version 3.4.3, which fixes the authorization check.
How can I assess whether this may have been exploited?
Review use of the batch-copy and batch-move endpoints by authenticated users, particularly operations involving workflows from projects where the requesting user lacked the required permissions. The provided information does not specify log fields or detection signatures.