Impact
An improper authorization flaw in Apache DolphinScheduler allows a user who only has read permission for a project to alter that project's workflow instances. The fault arises because the PUT /projects/{projectCode}/workflow‑instances/{id} endpoint does not enforce the required write permission, enabling modifications to workflow configurations that the user should not be able to change.
Affected Systems
Vulnerable systems are Apache DolphinScheduler installations running any version before 3.4.3. All earlier releases lack the patch that corrects missing permission checks.
Risk and Exploitability
The exploit requires only authenticated access with project‑read rights, which are commonly granted. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the ability to rewrite workflow definitions can lead to unintended executions or further compromise. The attack is internal and requires the target to provide credentials that grant read access to a project. Because no public exploitation has been documented, the risk is high but not yet demonstrated; administrators should consider the flaw a serious security concern.
OpenCVE Enrichment