CVE-2026-71898
Published 29 September 2026 · tracked since 30 September 2026
Description
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97395
- CVE-2026-71899
- CVE-2026-78214 MEDIUM 5.3
- CVE-2026-81569 MEDIUM 4.3
- CVE-2026-71897 MEDIUM 4.3
- CVE-2026-98164
- CVE-2026-82804 HIGH 8.8
- CVE-2026-82973 CRITICAL 9.4
- CVE-2026-73599 MEDIUM 5.4
- CVE-2026-100823