Severity: moderate 

Affected versions:

- Apache DolphinScheduler before 3.4.3

Description:

An incorrect authorization check in Apache DolphinScheduler allows an 
authenticated user with only read permission for a project to modify a workflow 
instance in that project through the PUT 
/projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not 
enforce the write permission required for this operation, allowing the user to 
make unauthorized changes to workflow instances.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Credit:

Dipak Panchal (finder)

References:

https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-71898

Reply via email to