Description
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution.

An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-09-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary command execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the way the scriptPath parameter is incorporated into a /bin/sh -c command without proper neutralization of shell metacharacters. This flaw permits an authenticated user to embed shell command substitution syntax, such as $(...), into a resource filename. When the Alert Script plugin triggers the /test-send endpoint, the injected syntax is interpreted by the shell, allowing the attacker to execute arbitrary commands with the privileges of the DolphinScheduler service process. The result is a full remote code execution that could compromise the underlying host and any dependent services.

Affected Systems

Apache DolphinScheduler versions prior to 3.4.3 are affected. Organizations running these versions should review their deployments and confirm the version in use.

Risk and Exploitability

The flaw is a high-severity command injection (CWE‑78). While the CVSS score is not provided, the fact that it allows execution of arbitrary commands with service-level privileges indicates a severe impact. Exploitation requires a valid authenticated session, which is typical in many operational environments. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, but the nature of the vulnerability warrants prompt remediation to mitigate the immediate risk.

Generated by OpenCVE AI on September 29, 2026 at 17:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache DolphinScheduler to version 3.4.3 or later to apply the fix that neutralizes the scriptPath input.
  • If an upgrade cannot be performed immediately, restrict the creation of resources that include shell metacharacters by enforcing strict input validation policies on the Alert Script plugin endpoint.
  • Apply network segmentation or firewall rules to limit access to the DolphinScheduler service from untrusted hosts, thereby reducing the attack surface for authenticated users attempting to exploit the vulnerability.

Generated by OpenCVE AI on September 29, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
References

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Command Injection in the Alert Script Plugin
Weaknesses CWE-78
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T20:17:24.648Z

Reserved: 2026-08-31T04:28:55.113Z

Link: CVE-2026-82804

cve-icon Vulnrichment

Updated: 2026-09-29T15:08:45.280Z

cve-icon NVD

Status : Deferred

Published: 2026-09-29T13:17:52.843

Modified: 2026-09-29T21:19:33.293

Link: CVE-2026-82804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:15:08Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')