CVE-2026-71896
- EPSS 0.16%
- Veröffentlicht 08.10.2026 08:39:21
- Zuletzt bearbeitet 08.10.2026 17:25:38
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce...
CVE-2026-71895
- EPSS 0.17%
- Veröffentlicht 08.10.2026 08:37:21
- Zuletzt bearbeitet 08.10.2026 17:25:38
An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that m...
CVE-2026-71183
- EPSS 0.15%
- Veröffentlicht 08.10.2026 08:34:48
- Zuletzt bearbeitet 08.10.2026 17:25:38
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail t...
CVE-2026-66087
- EPSS 0.16%
- Veröffentlicht 08.10.2026 08:29:43
- Zuletzt bearbeitet 08.10.2026 21:18:02
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the * /dolphinscheduler/projects/{projectCode}/task-instances/{taskIns...
CVE-2026-66084
- EPSS 0.18%
- Veröffentlicht 08.10.2026 08:18:19
- Zuletzt bearbeitet 08.10.2026 21:18:01
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upst...
CVE-2026-66082
- EPSS 0.19%
- Veröffentlicht 08.10.2026 08:16:38
- Zuletzt bearbeitet 08.10.2026 21:18:01
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissi...
CVE-2026-81569
- EPSS 0.23%
- Veröffentlicht 29.09.2026 14:17:21
- Zuletzt bearbeitet 29.09.2026 16:17:11
An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow t...
CVE-2026-78214
- EPSS 0.35%
- Veröffentlicht 29.09.2026 14:17:21
- Zuletzt bearbeitet 29.09.2026 16:17:11
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafte...
CVE-2026-71899
- EPSS 0.15%
- Veröffentlicht 29.09.2026 14:17:21
- Zuletzt bearbeitet 01.10.2026 16:17:50
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticate...
CVE-2026-71898
- EPSS 0.18%
- Veröffentlicht 29.09.2026 14:17:21
- Zuletzt bearbeitet 29.09.2026 16:17:09
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. T...