Apache DolphinScheduler 中存在一个授权绕过漏洞,允许已认证用户对非所属项目中的工作流调度、工作流定义和任务实例执行未经授权的操作。 受影响的端点在验证权限时仅检查提供的 ,但未验证目标资源是否确实属于该项目。具有某一项目相应权限的已认证用户,可以通过提供该项目的 以及另一个项目的资源标识符,从而绕过目标项目的访问限制。 受影响的端点包括: 和 :可激活或停用其他项目中的工作流调度。 :可更改其他项目中工作流定义的 ONLINE/OFFLINE 状态。 成功利用此漏洞后,攻击者可以更改非授权访
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | 0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71896 | Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of Use | |
| CVE-2026-71895 | Apache DolphinScheduler: Missing Authorization Checks Allow Non-Admin Users to Retrieve Ku | |
| CVE-2026-71183 | Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Info | |
| CVE-2026-66087 | Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint | |
| CVE-2026-66084 | Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream |
No comments yet