CVE-2026-82804 Details
Description
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
A command injection vulnerability has been identified in the Apache DolphinScheduler Alert Script plugin, affecting versions prior to 3.4.3. The issue arises because the scriptPath parameter is passed into a shell command without proper sanitization of shell metacharacters. This flaw allows authenticated users to exploit the vulnerability by creating a resource with a filename that includes shell command substitution syntax, such as $(...). They can then send this crafted path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the injected command is processed by the shell, leading to arbitrary command execution with the privileges of the DolphinScheduler service process.
Users are advised to upgrade to Apache DolphinScheduler version 3.4.3 or later, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/29/25 | CVE | |
| https://lists.apache.org/thread.html/mwzbs5qdhs7nblfz70jgs0z54qx3phql | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache DolphinScheduler | < 3.4.3 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | CVE Modified | CVE |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion