CVE WATCH / VULNERABILITY DETAIL

CVE-2026-71897

MEDIUMCVSS 4.3NVD feed

Published 29 September 2026 · tracked since 30 September 2026

Description

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.Th

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-71897 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-71897

MEDIUMCVSS 4.3NVD feed

Published 29 September 2026 · tracked since 30 September 2026

Description

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.Th

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]