Apache Dolphinscheduler

Apache · 40 CVEs

CVE-2026-71897
MEDIUM

Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints

Sep 29, 2026

CVE-2026-71898
MEDIUM

Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Wor…

Sep 29, 2026

CVE-2026-71899
MEDIUM

Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure

Sep 29, 2026

CVE-2026-78214
MEDIUM

Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths

Sep 29, 2026

CVE-2026-81569
MEDIUM

Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution

Sep 29, 2026

CVE-2026-82804
HIGH

Apache DolphinScheduler: Command Injection in the Alert Script Plugin

Sep 29, 2026

CVE-2026-66083
MEDIUM

Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource

Sep 29, 2026

CVE-2026-57590
HIGH

Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations

Sep 24, 2026

CVE-2026-49050
HIGH

Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens

Aug 25, 2026

CVE-2026-47340
MEDIUM

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances…

Jun 17, 2026

CVE-2026-32967
CRITICAL

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Jun 17, 2026

CVE-2026-42357
MEDIUM

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information bel…

Jun 17, 2026

CVE-2026-41280
MEDIUM

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task…

Jun 17, 2026

CVE-2026-32966
CRITICAL

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

Jun 17, 2026

CVE-2026-23902
HIGH

Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution.

Apr 24, 2026

CVE-2025-62233
MEDIUM

Apache DolphinScheduler: Deserialization of untrusted data in RPC

Apr 24, 2026

CVE-2025-62188
HIGH

Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint.

Apr 9, 2026

CVE-2024-43166
CRITICAL

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef…

Sep 3, 2025

CVE-2024-43115
HIGH

Apache DolphinScheduler: Alert Script Attack

Sep 3, 2025

CVE-2024-43202
CRITICAL

Apache DolphinScheduler: Remote Code Execution Vulnerability

Aug 20, 2024

CVE-2024-30188
HIGH

Apache DolphinScheduler: Resource File Read And Write Vulnerability

Aug 9, 2024

CVE-2024-29831
HIGH

Apache DolphinScheduler: RCE by arbitrary js execution

Aug 9, 2024

CVE-2024-23320
HIGH

Apache DolphinScheduler: Arbitrary js execution as root for authenticated users

Feb 23, 2024

CVE-2023-51770
HIGH

Apache DolphinScheduler: Arbitrary File Read Vulnerability

Feb 20, 2024

CVE-2023-50270
MEDIUM

Apache DolphinScheduler: Session do not expire after password change

Feb 20, 2024

Showing 1 to 25 of 40 CVEs