CVE WATCH / VULNERABILITY DETAIL

CVE-2026-71898

MEDIUMCVSS 4.3NVD feed

Published 29 September 2026 · tracked since 30 September 2026

Description

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-71898 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-71898

MEDIUMCVSS 4.3NVD feed

Published 29 September 2026 · tracked since 30 September 2026

Description

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]