Apache Dolphinscheduler
Apache · 40 CVEs
Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
Sep 29, 2026
Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Wor…
Sep 29, 2026
Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure
Sep 29, 2026
Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
Sep 29, 2026
Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution
Sep 29, 2026
Apache DolphinScheduler: Command Injection in the Alert Script Plugin
Sep 29, 2026
Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
Sep 29, 2026
Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations
Sep 24, 2026
Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens
Aug 25, 2026
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances…
Jun 17, 2026
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Jun 17, 2026
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information bel…
Jun 17, 2026
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task…
Jun 17, 2026
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Jun 17, 2026
Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution.
Apr 24, 2026
Apache DolphinScheduler: Deserialization of untrusted data in RPC
Apr 24, 2026
Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint.
Apr 9, 2026
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef…
Sep 3, 2025
Apache DolphinScheduler: Alert Script Attack
Sep 3, 2025
Apache DolphinScheduler: Remote Code Execution Vulnerability
Aug 20, 2024
Apache DolphinScheduler: Resource File Read And Write Vulnerability
Aug 9, 2024
Apache DolphinScheduler: RCE by arbitrary js execution
Aug 9, 2024
Apache DolphinScheduler: Arbitrary js execution as root for authenticated users
Feb 23, 2024
Apache DolphinScheduler: Arbitrary File Read Vulnerability
Feb 20, 2024
Apache DolphinScheduler: Session do not expire after password change
Feb 20, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-71897 | Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints | MEDIUM | 0.18% | Sep 29, 2026 |
| CVE-2026-71898 | Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions | MEDIUM | 0.18% | Sep 29, 2026 |
| CVE-2026-71899 | Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure | MEDIUM | 0.23% | Sep 29, 2026 |
| CVE-2026-78214 | Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths | MEDIUM | 0.35% | Sep 29, 2026 |
| CVE-2026-81569 | Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution | MEDIUM | 0.23% | Sep 29, 2026 |
| CVE-2026-82804 | Apache DolphinScheduler: Command Injection in the Alert Script Plugin | HIGH | 0.50% | Sep 29, 2026 |
| CVE-2026-66083 | Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource | MEDIUM | 0.23% | Sep 29, 2026 |
| CVE-2026-57590 | Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations | HIGH | 0.23% | Sep 24, 2026 |
| CVE-2026-49050 | Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens | HIGH | 0.58% | Aug 25, 2026 |
| CVE-2026-47340 | Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not… | MEDIUM | 0.55% | Jun 17, 2026 |
| CVE-2026-32967 | Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks | CRITICAL | 0.55% | Jun 17, 2026 |
| CVE-2026-42357 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have perm… | MEDIUM | 0.49% | Jun 17, 2026 |
| CVE-2026-41280 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects | MEDIUM | 0.54% | Jun 17, 2026 |
| CVE-2026-32966 | Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure | CRITICAL | 0.66% | Jun 17, 2026 |
| CVE-2026-23902 | Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution. | HIGH | 0.45% | Apr 24, 2026 |
| CVE-2025-62233 | Apache DolphinScheduler: Deserialization of untrusted data in RPC | MEDIUM | 0.54% | Apr 24, 2026 |
| CVE-2025-62188 | Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint. | HIGH | 0.52% | Apr 9, 2026 |
| CVE-2024-43166 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgr… | CRITICAL | 0.52% | Sep 3, 2025 |
| CVE-2024-43115 | Apache DolphinScheduler: Alert Script Attack | HIGH | 0.51% | Sep 3, 2025 |
| CVE-2024-43202 | Apache DolphinScheduler: Remote Code Execution Vulnerability | CRITICAL | 2.15% | Aug 20, 2024 |
| CVE-2024-30188 | Apache DolphinScheduler: Resource File Read And Write Vulnerability | HIGH | 5.99% | Aug 9, 2024 |
| CVE-2024-29831 | Apache DolphinScheduler: RCE by arbitrary js execution | HIGH | 1.18% | Aug 9, 2024 |
| CVE-2024-23320 | Apache DolphinScheduler: Arbitrary js execution as root for authenticated users | HIGH | 1.39% | Feb 23, 2024 |
| CVE-2023-51770 | Apache DolphinScheduler: Arbitrary File Read Vulnerability | HIGH | 1.24% | Feb 20, 2024 |
| CVE-2023-50270 | Apache DolphinScheduler: Session do not expire after password change | MEDIUM | 1.31% | Feb 20, 2024 |
Showing 1 to 25 of 40 CVEs