CVE-2026-71897
Published 29 September 2026 · tracked since 30 September 2026
Description
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.Th
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97395
- CVE-2026-71898 MEDIUM 4.3
- CVE-2026-71899
- CVE-2026-78214 MEDIUM 5.3
- CVE-2026-81569 MEDIUM 4.3
- CVE-2026-98164
- CVE-2026-82804 HIGH 8.8
- CVE-2026-82973 CRITICAL 9.4
- CVE-2026-73599 MEDIUM 5.4
- CVE-2026-100823