CVE-2026-78214 Details
Description
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated attacker can cause the security check to fail to recognize the request as targeting a protected endpoint. As a result, the attacker may bypass authentication and access otherwise restricted Actuator endpoints. Successful exploitation may expose operational or configuration information and, depending on the enabled endpoints and application configuration, allow access to sensitive management functionality. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
A vulnerability allowing authentication bypass on Actuator endpoints has been identified in Apache DolphinScheduler versions prior to 3.4.3. This issue arises because the application determines authentication requirements by matching incoming request paths against protected Actuator paths. By sending a specially crafted request with a percent-encoded path, a remote unauthenticated attacker can manipulate the security check, causing it to overlook the request as targeting a protected endpoint. Consequently, the attacker can bypass authentication and access restricted Actuator endpoints. Exploitation of this vulnerability may reveal operational or configuration information and, depending on the application's endpoint settings, could provide access to sensitive management functions.
Users are advised to upgrade to Apache DolphinScheduler version 3.4.3 or later, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/29/23 | CVE | |
| https://lists.apache.org/thread.html/88g4v2sjd9j2xgn64gnm7k4ocnj4rlob | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache DolphinScheduler | < 3.4.3 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | CVE Modified | CVE |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion