VYPR
Medium severity4.3NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026

CVE-2026-71898

CVE-2026-71898

Description

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances.

This issue affects Apache DolphinScheduler: before 3.4.3.

Users are recommended to upgrade to version 3.4.3, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.