Severity: moderate
Affected versions:
- Apache DolphinScheduler before 3.4.3
Description:
An incorrect authorization check in Apache DolphinScheduler allows an
authenticated user with only read permission for a project to modify a workflow
instance in that project through the PUT
/projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not
enforce the write permission required for this operation, allowing the user to
make unauthorized changes to workflow instances.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Credit:
Dipak Panchal (finder)
References:
https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-71898