Severity: low 

Affected versions:

- Apache DolphinScheduler (org.apache.dolphinscheduler:dolphinscheduler-api) 
before 3.4.3

Description:

An authentication bypass vulnerability exists in the protection of Actuator 
endpoints. The application determines whether authentication is required by 
matching the incoming request path against protected Actuator paths. By sending 
a specially crafted request containing a percent-encoded path, a remote 
unauthenticated attacker can cause the security check to fail to recognize the 
request as targeting a protected endpoint.



As a result, the attacker may bypass authentication and access otherwise 
restricted Actuator endpoints. Successful exploitation may expose operational 
or configuration information and, depending on the enabled endpoints and 
application configuration, allow access to sensitive management functionality.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Credit:

Xmirror Security Team (finder)

References:

https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-78214

Reply via email to