Apache DolphinScheduler 中存在一个权限绕过漏洞,允许已认证用户通过 端点,修改其无权访问的项目中的任务定义。 该端点未验证由 标识的任务定义是否属于由 指定的项目。已认证用户可以提供其有权访问的项目代码,并结合另一个项目中的任务定义代码,从而绕过项目访问限制,修改目标任务定义及其上游依赖项。 此漏洞可能破坏工作流的完整性,并导致未经授权项目中的任务执行中断。该问题影响 Apache DolphinScheduler 3.4.3 之前的所有版本。 建议用户升级至 3.4.3 版本,该版本已修复
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | 0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71896 | Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of Use | |
| CVE-2026-71895 | Apache DolphinScheduler: Missing Authorization Checks Allow Non-Admin Users to Retrieve Ku | |
| CVE-2026-71183 | Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Info | |
| CVE-2026-66087 | Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint | |
| CVE-2026-66082 | Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (sch |
No comments yet