Description
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-09-29
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Authenticated users with read‑only project access can modify workflow instances
Action: Immediate Patch
AI Analysis

Impact

An improper authorization flaw in Apache DolphinScheduler allows a user who only has read permission for a project to alter that project's workflow instances. The fault arises because the PUT /projects/{projectCode}/workflow‑instances/{id} endpoint does not enforce the required write permission, enabling modifications to workflow configurations that the user should not be able to change.

Affected Systems

Vulnerable systems are Apache DolphinScheduler installations running any version before 3.4.3. All earlier releases lack the patch that corrects missing permission checks.

Risk and Exploitability

The exploit requires only authenticated access with project‑read rights, which are commonly granted. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the ability to rewrite workflow definitions can lead to unintended executions or further compromise. The attack is internal and requires the target to provide credentials that grant read access to a project. Because no public exploitation has been documented, the risk is high but not yet demonstrated; administrators should consider the flaw a serious security concern.

Generated by OpenCVE AI on September 29, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache DolphinScheduler to version 3.4.3 or newer, which removes the incorrect authorization check.
  • After upgrading, verify that project users possess only the required permissions and that read‑only accounts cannot perform write actions.
  • If possible, configure the application or network rules to block or restrict the PUT /projects/{projectCode}/workflow‑instances/{id} endpoint for users lacking write rights.
  • Monitor workflow and audit logs for unexpected modifications to workflow instances after applying the patch.

Generated by OpenCVE AI on September 29, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T15:45:34.658Z

Reserved: 2026-08-08T01:26:32.726Z

Link: CVE-2026-71898

cve-icon Vulnrichment

Updated: 2026-09-29T15:08:41.439Z

cve-icon NVD

Status : Deferred

Published: 2026-09-29T14:17:21.067

Modified: 2026-09-29T16:17:09.620

Link: CVE-2026-71898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:30:07Z

Weaknesses