Executive brief
Apache DolphinScheduler is a workflow scheduling platform used to manage and automate data pipelines and job orchestration. A privilege escalation vulnerability allows regular users to generate administrative access tokens through an unprotected API endpoint, effectively granting them full administrative privileges. This enables attackers with basic user accounts to take over the entire system, access sensitive data, and compromise all workflows and scheduling operations.
Technical details
This is a privilege escalation vulnerability in the /access-tokens API endpoint of Apache DolphinScheduler. The vulnerable endpoint lacks proper authorization checks, allowing authenticated general users to mint administrative access tokens without elevated privileges. The attack requires network access to the API endpoint and an existing user account (low-privilege user authentication is sufficient). An attacker exploiting this flaw gains full administrative capabilities, enabling complete system compromise including user management, workflow execution, and data access.
Affected products
- Apache DolphinScheduler before 3.4.2
Timeline
- 2026-08-25: disclosed