Vulnerabilities

Summary — last 7 days

New vulnerabilities2,624▼ 224 vs. last week
Critical / high1,373▲ 143 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
–

41 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (4.3)0.23%—Apache DolphinschedulerAI9/29/20269/29/2026
An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system does not properly verify whether the user has…
DeferredMedium (5.3)0.35%—Apache DolphinschedulerAI9/29/20269/29/2026
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated…
DeferredMedium (6.5)0.23%—Apache DolphinschedulerAI9/29/202610/1/2026
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can…
DeferredMedium (4.3)0.18%—Apache DolphinschedulerAI9/29/20269/29/2026
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this…
DeferredMedium (4.3)0.18%—Apache DolphinschedulerAI9/29/20269/29/2026
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects…
DeferredHigh (8.8)0.50%—Apache DolphinschedulerAI9/29/20269/29/2026
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as…
Awaiting AnalysisMedium (6.5)0.23%—Apache DolphinschedulerAI9/29/20269/29/2026
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields…
Awaiting AnalysisHigh (8.1)0.23%—Apache DolphinschedulerAI9/24/20269/24/2026
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are…
AnalyzedHigh (8.8)0.58%—Apache Dolphinscheduler8/25/20269/28/2026
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
ModifiedMedium (6.5)0.55%—Apache Dolphinscheduler6/17/20266/17/2026
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
ModifiedMedium (6.5)0.49%—Apache Dolphinscheduler6/17/20266/17/2026
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
AnalyzedMedium (4.9)0.54%—Apache Dolphinscheduler6/17/20266/17/2026
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
ModifiedCritical (9.1)0.55%—Apache Dolphinscheduler6/17/20266/17/2026
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
ModifiedCritical (9.8)0.66%—Apache Dolphinscheduler6/17/20266/17/2026
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
AnalyzedHigh (8.1)0.45%—Apache Dolphinscheduler4/24/20266/17/2026
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1,…
AnalyzedMedium (6.3)0.54%—Apache Dolphinscheduler4/24/20269/30/2026
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and…
AnalyzedHigh (7.5)0.52%—Apache Dolphinscheduler4/9/20269/30/2026
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are recommended to upgrade…
ModifiedCritical (9.8)0.52%—Apache Dolphinscheduler9/3/20256/17/2026
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
ModifiedHigh (8.8)0.51%—Apache Dolphinscheduler9/3/20256/17/2026
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
AnalyzedCritical (9.8)2.1%—Apache Dolphinscheduler8/20/20246/17/2026
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
ModifiedHigh (8.1)6.0%—Apache Dolphinscheduler8/12/20246/17/2026
File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue.
AnalyzedHigh (8.8)1.2%—Apache Dolphinscheduler8/12/20246/17/2026
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
AnalyzedHigh (8.8)1.4%—Apache Dolphinscheduler2/23/20246/17/2026
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it. This issue affects Apache…
ModifiedHigh (7.5)1.2%—Apache Dolphinscheduler2/20/20246/17/2026
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
AnalyzedMedium (6.5)1.3%—Apache Dolphinscheduler2/20/20246/17/2026
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.