Description
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Authorization Bypass – an authenticated user can copy or move workflows into projects without permission
Action: Immediate Patch
AI Analysis

Impact

Apache DolphinScheduler contains an improper authorization check that allows an authenticated user to invoke the batch‑copy and batch‑move endpoints and operate on workflows in projects for which they lack the required permissions. The flaw is an example of CWE‑863, where the system fails to enforce proper access control, enabling the user to copy or move workflows from unauthorized projects. This can lead to privilege escalation and unauthorized data exposure within the scheduler environment.

Affected Systems

All users of the Apache Software Foundation’s Apache DolphinScheduler, specifically installations running any version prior to 3.4.3. The vulnerability applies to the batch‑copy and batch‑move features accessible by authenticated accounts.

Risk and Exploitability

The issue requires the attacker to be authenticated and to have some baseline permissions within DolphinScheduler, but the flaw permits extrapolation of privileges to other projects. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, implying that no public exploit is known at this time. Nevertheless, the CVSS score is not provided, so the precise severity cannot be quantified here; the potential for unauthorized workflow manipulation remains significant.

Generated by OpenCVE AI on September 29, 2026 at 15:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading Apache DolphinScheduler to version 3.4.3 or newer.
  • If an immediate upgrade is not possible, disable the batch‑copy and batch‑move endpoints to prevent unauthorized workflow operations.
  • Review and tighten project access controls and monitor scheduler logs for suspicious workflow activity.

Generated by OpenCVE AI on September 29, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache dolphinscheduler
Vendors & Products Apache
Apache dolphinscheduler

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
Weaknesses CWE-863
References

Subscriptions

Apache Dolphinscheduler
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T15:44:29.941Z

Reserved: 2026-08-08T01:22:04.866Z

Link: CVE-2026-71897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-29T14:17:20.947

Modified: 2026-09-29T15:54:00.483

Link: CVE-2026-71897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:30:07Z

Weaknesses