CVE-2026-71899 Details
Description
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can invoke the API with parameters referencing workflows belonging to that project and retrieve workflow information. This allows users to access workflow data outside their authorized project scope, resulting in unauthorized information disclosure. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
A missing authorization vulnerability has been identified in the query-dynamic-sub-workflows API of Apache DolphinScheduler versions 3.2.0 prior to 3.4.3. This vulnerability arises because the API fails to properly verify whether an authenticated user has the necessary permissions to access the workflows being queried. As a result, an authenticated user without permission to access a specific project can invoke the API with parameters referencing workflows from that project, thereby retrieving workflow information. This exploitation allows access to workflow data beyond the user's authorized project scope, leading to unauthorized information disclosure.
Users are advised to upgrade to Apache DolphinScheduler version 3.4.3, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/29/22 | CVE | |
| https://lists.apache.org/thread.html/qcork1j6q52xsp419vgb5dsstp9mxk09 | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache DolphinScheduler | >= 3.2.0, < 3.4.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CVE |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion