VYPR
Medium severity4.3NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026

CVE-2026-71897

CVE-2026-71897

Description

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.

This issue affects Apache DolphinScheduler: before 3.4.3.

Users are recommended to upgrade to version 3.4.3, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.