CVE-2026-71899
Published 29 September 2026 · tracked since 30 September 2026
Description
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried.An authenticated user who does not have permission to access a sp
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97395
- CVE-2026-71898 MEDIUM 4.3
- CVE-2026-78214 MEDIUM 5.3
- CVE-2026-81569 MEDIUM 4.3
- CVE-2026-71897 MEDIUM 4.3
- CVE-2026-98164
- CVE-2026-82804 HIGH 8.8
- CVE-2026-82973 CRITICAL 9.4
- CVE-2026-73599 MEDIUM 5.4
- CVE-2026-100823