Apache DolphinScheduler

8 known vulnerabilities in Apache DolphinScheduler, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-81569 CVSS 4.3 medium An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission…
  • CVE-2026-78214 CVSS 5.3 medium An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication…
  • CVE-2026-71899 CVSS 6.5 medium A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not…
  • CVE-2026-71898 CVSS 4.3 medium An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify…
  • CVE-2026-71897 CVSS 4.3 medium An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to…
  • CVE-2026-82804 CVSS 8.8 high The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing…
  • CVE-2026-66083 CVSS 6.5 medium The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this…
  • CVE-2026-57590 CVSS 8.1 high A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify…