Description
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated attacker can cause the security check to fail to recognize the request as targeting a protected endpoint.



As a result, the attacker may bypass authentication and access otherwise restricted Actuator endpoints. Successful exploitation may expose operational or configuration information and, depending on the enabled endpoints and application configuration, allow access to sensitive management functionality.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-09-29
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

An attacker who sends a request with a percent-encoded path can bypass the authentication checks that protect Actuator endpoints. The vulnerability stems from the way the application matches incoming request paths against protected endpoints, allowing the security logic to miss requests that are encoded. This flaw is a classic example of the improper use of path handling identified as CWE-863. When bypassed, the attacker can access management functions or view operational configuration that are normally restricted to authenticated users. The impact is the potential disclosure of sensitive data or unauthorized control of application behavior.

Affected Systems

The flaw affects Apache DolphinScheduler installations running any version prior to 3.4.3. The affected vendor is the Apache Software Foundation. If your deployment uses an older release, it is susceptible to this bypass. All other versions are unaffected.

Risk and Exploitability

Because the vulnerability does not require additional privileges or local access, a remote, unauthenticated attacker can exploit it over the network by crafting a single HTTP request. No EPSS score is available, but the nature of the bug – an unchecked authentication bypass – indicates a high likelihood of exploitation in environments where Actuator endpoints are left enabled and reachable. The flaw is not yet listed in the CISA KEV catalog, yet the risk remains significant due to the potential for information disclosure or misuse of management features.

Generated by OpenCVE AI on September 29, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading Apache DolphinScheduler to version 3.4.3 or later.
  • If an upgrade cannot be performed immediately, temporarily disable all Actuator endpoints or remove permission for unauthenticated access through configuration changes.
  • Implement network segmentation or firewall rules to restrict external access to the Actuator service, ensuring only trusted internal hosts can reach it.

Generated by OpenCVE AI on September 29, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated attacker can cause the security check to fail to recognize the request as targeting a protected endpoint. As a result, the attacker may bypass authentication and access otherwise restricted Actuator endpoints. Successful exploitation may expose operational or configuration information and, depending on the enabled endpoints and application configuration, allow access to sensitive management functionality. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T15:46:35.676Z

Reserved: 2026-08-24T02:06:43.203Z

Link: CVE-2026-78214

cve-icon Vulnrichment

Updated: 2026-09-29T15:08:43.314Z

cve-icon NVD

Status : Deferred

Published: 2026-09-29T14:17:21.530

Modified: 2026-09-29T16:17:11.617

Link: CVE-2026-78214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:30:07Z

Weaknesses