Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache DolphinScheduler — Vulnerabilities & Security Advisories 40

All 40 CVE vulnerabilities found in Apache DolphinScheduler, with AI-generated Chinese analysis, references, and POCs.

This page aggregates documented security vulnerabilities for Apache DolphinScheduler, an open-source workflow scheduling platform. The collection includes all known security flaws affecting the product, covering the time range from its initial release to the most recent advisories. Here, you can track vendor-issued security advisories, analyze specific weakness classes such as injection flaws and access control defects, and review the complete vulnerability history for Apache DolphinScheduler. The data is organized to support audit, risk assessment, and patch planning for teams relying on this distributed task scheduling system.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-71897 Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints CWE-863 - - 2026-09-29
CVE-2026-71898 Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions CWE-863 - - 2026-09-29
CVE-2026-71899 Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure CWE-863 - - 2026-09-29
CVE-2026-78214 Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths CWE-863 - - 2026-09-29
CVE-2026-81569 Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution - - 2026-09-29
CVE-2026-82804 Apache DolphinScheduler: Command Injection in the Alert Script Plugin CWE-78 - - 2026-09-29
CVE-2026-66083 Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource CWE-306 - - 2026-09-29
CVE-2026-57590 Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations CWE-863 - - 2026-09-24
CVE-2026-49050 Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens CWE-863 - - 2026-08-25
CVE-2026-47340 Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access. CWE-200 - - 2026-06-17
CVE-2026-32967 Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks CWE-863 - - 2026-06-17
CVE-2026-42357 Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. CWE-863 - - 2026-06-17
CVE-2026-41280 Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects CWE-863 - - 2026-06-17
CVE-2026-32966 Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure CWE-863 - - 2026-06-17
CVE-2026-23902 Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution. CWE-863 8.8AI High AI 2026-04-24
CVE-2025-62233 Apache DolphinScheduler: Deserialization of untrusted data in RPC CWE-502 8.8AI High AI 2026-04-24
CVE-2025-62188 Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint. CWE-200 7.5AI High AI 2026-04-09
CVE-2024-43166 Apache DolphinScheduler 安全漏洞 CWE-276 9.8AI Critical AI 2025-09-03
CVE-2024-43115 Apache DolphinScheduler: Alert Script Attack CWE-20 8.8AI High AI 2025-09-03
CVE-2024-43202 Apache DolphinScheduler: Remote Code Execution Vulnerability CWE-94 9.8AI Critical AI 2024-08-20
CVE-2024-30188 Apache DolphinScheduler: Resource File Read And Write Vulnerability CWE-20 8.1AI High AI 2024-08-09
CVE-2024-29831 Apache DolphinScheduler: RCE by arbitrary js execution CWE-20 8.2AI High AI 2024-08-09
CVE-2024-23320 Apache DolphinScheduler: Arbitrary js execution as root for authenticated users CWE-20 5.4 - 2024-02-23
CVE-2023-51770 Apache DolphinScheduler: Arbitrary File Read Vulnerability CWE-94 7.5AI High AI 2024-02-20
CVE-2023-50270 Apache DolphinScheduler: Session do not expire after password change CWE-613 9.1AI Critical AI 2024-02-20
CVE-2023-49250 Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtil CWE-295 7.4AI High AI 2024-02-20
CVE-2023-49109 Remote Code Execution in Apache Dolphinscheduler CWE-94 9.8AI Critical AI 2024-02-20
CVE-2023-49299 Apache DolphinScheduler: Arbitrary js execute as root for authenticated users CWE-20 8.2 - 2023-12-30
CVE-2023-49620 Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for CWE-862 4.3 - 2023-11-30
CVE-2023-49068 Apache DolphinScheduler: Information Leakage Vulnerability CWE-200 7.5 - 2023-11-27

All 40 known CVE vulnerabilities affecting Apache DolphinScheduler with full Chinese analysis, references, and POCs where available.