Apache DolphinScheduler 中存在一个授权绕过漏洞,允许已认证用户通过以下 API 接口操作其无权访问的项目中的任务实例: 此问题影响 Apache DolphinScheduler 3.4.3 之前的版本。 建议用户升级至 3.4.3 版本,该版本已修复此漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | 0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71896 | Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of Use | |
| CVE-2026-71895 | Apache DolphinScheduler: Missing Authorization Checks Allow Non-Admin Users to Retrieve Ku | |
| CVE-2026-71183 | Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Info | |
| CVE-2026-66084 | Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream | |
| CVE-2026-66082 | Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (sch |
No comments yet