« Back to list

Apache

Apache Dolphinscheduler: vulnerabilities and CVEs

Apache Dolphinscheduler has 41 published vulnerabilities, 17 of them in the last 12 months. 8 are rated critical and 0 are listed by CISA as actively exploited.

CVEs41
Last 12 months17
Critical8
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-81569Medium (4.3)0.23%—Sep 29, 2026
An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that…
CVE-2026-78214Medium (5.3)0.35%—Sep 29, 2026
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator…
CVE-2026-71899Medium (6.5)0.23%—Sep 29, 2026
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows…
CVE-2026-71898Medium (4.3)0.18%—Sep 29, 2026
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT…
CVE-2026-71897Medium (4.3)0.18%—Sep 29, 2026
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions.…
CVE-2026-82804High (8.8)0.50%—Sep 29, 2026
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this…
CVE-2026-66083Medium (6.5)0.23%—Sep 29, 2026
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access.…
CVE-2026-57590High (8.1)0.23%—Sep 24, 2026
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated…
CVE-2026-49050High (8.8)0.58%—Aug 25, 2026
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CVE-2026-47340Medium (6.5)0.55%—Jun 17, 2026
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are…
CVE-2026-42357Medium (6.5)0.49%—Jun 17, 2026
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2.…
CVE-2026-41280Medium (4.9)0.54%—Jun 17, 2026
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are…
CVE-2026-32967Critical (9.1)0.55%—Jun 17, 2026
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes…
CVE-2026-32966Critical (9.8)0.66%—Jun 17, 2026
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to…
CVE-2026-23902High (8.1)0.45%—Apr 24, 2026
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects…
CVE-2025-62233Medium (6.3)0.54%—Apr 24, 2026
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can…
CVE-2025-62188High (7.5)0.52%—Apr 9, 2026
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database…
CVE-2024-43166Critical (9.8)0.52%—Sep 3, 2025
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
CVE-2024-43115High (8.8)0.51%—Sep 3, 2025
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are…
CVE-2024-43202Critical (9.8)2.1%—Aug 20, 2024
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
CVE-2024-30188High (8.1)6.0%—Aug 12, 2024
File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are…
CVE-2024-29831High (8.8)1.2%—Aug 12, 2024
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade…
CVE-2024-23320High (8.8)1.4%—Feb 23, 2024
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix…
CVE-2023-51770High (7.5)1.2%—Feb 20, 2024
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
CVE-2023-50270Medium (6.5)1.3%—Feb 20, 2024
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
CVE-2023-49250High (7.3)0.70%—Feb 20, 2024
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache…
CVE-2023-49109Critical (9.8)2.3%—Feb 20, 2024
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
CVE-2023-49299High (8.8)1.4%—Dec 30, 2023
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.…
CVE-2023-49620Medium (6.5)1.1%—Nov 30, 2023
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0…
CVE-2023-49068High (7.5)1.1%—Nov 27, 2023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services10
  2. T1078 Valid Accounts5
  3. T1190 Exploit Public-Facing Application5
  4. T1078.001 Default Accounts2
  5. T1552.007 Container API2
  6. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Apache