Severity: moderate 

Affected versions:

- Apache DolphinScheduler before 3.4.3

Description:

An improper authorization check in Apache DolphinScheduler allows an 
authenticated user to use the batch-copy and batch-move endpoints to operate on 
workflows in projects for which they lack the required permissions. This may 
allow the user to copy or move workflows from unauthorized projects.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Credit:

n0mi1k (finder)
Yeonoh Park (finder)

References:

https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-71897

Reply via email to