VendorsApachedolphinschedulerall versions
Vulnerabilities

Apache Software Foundation DolphinScheduler

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2020-11974
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
Published 2020-12-18 · Modified
9.8EPSS 0.081
CVE-2022-45462
Apache DolphinScheduler prior to 2.0.5 have command execution vulnerability
Published 2022-11-23 · Modified
9.8EPSS 0.028
CVE-2022-45875
Apache DolphinScheduler: Remote command execution Vulnerability in script alert plugin
Published 2023-01-04 · Modified
9.8EPSS 0.026
CVE-2023-49109
Remote Code Execution in Apache Dolphinscheduler
Published 2024-02-20 · Analyzed
9.8EPSS 0.023
CVE-2024-43202
Apache DolphinScheduler: Remote Code Execution Vulnerability
Published 2024-08-20 · Analyzed
9.8EPSS 0.021
CVE-2026-32966
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Published 2026-06-17 · Modified
9.8EPSS 0.007
CVE-2024-43166
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
Published 2025-09-03 · Modified
9.8EPSS 0.005
CVE-2026-32967
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Published 2026-06-17 · Modified
9.1EPSS 0.005
CVE-2024-30188
Apache DolphinScheduler: Resource File Read And Write Vulnerability
Published 2024-08-09 · Modified
8.8EPSS 0.060
CVE-2021-27644
DolphinScheduler mysql jdbc connector parameters deserialize remote code execution
Published 2021-11-01 · Modified
8.8EPSS 0.019
CVE-2023-49299
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Published 2023-12-30 · Modified
8.8EPSS 0.014
CVE-2024-23320
Apache DolphinScheduler: Arbitrary js execution as root for authenticated users
Published 2024-02-23 · Analyzed
8.8EPSS 0.014
CVE-2024-29831
Apache DolphinScheduler: RCE by arbitrary js execution
Published 2024-08-09 · Analyzed
8.8EPSS 0.012
CVE-2026-49050
Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens
Published 2026-08-25 · Analyzed
8.8EPSS 0.006
CVE-2024-43115
Apache DolphinScheduler: Alert Script Attack
Published 2025-09-03 · Modified
8.8EPSS 0.005
CVE-2026-23902
Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution.
Published 2026-04-24 · Analyzed
8.1EPSS 0.004
CVE-2022-25598
Apache DolphinScheduler user registration is vulnerable to ReDoS attacks
Published 2022-03-30 · Modified
7.5EPSS 0.020
CVE-2022-26885
Apache DolphinScheduler config file read by task risk
Published 2022-11-24 · Modified
7.5EPSS 0.013
CVE-2023-51770
Apache DolphinScheduler: Arbitrary File Read Vulnerability
Published 2024-02-20 · Modified
7.5EPSS 0.012
CVE-2023-48796
Apache dolphinscheduler sensitive information disclosure
Published 2023-11-24 · Modified
7.5EPSS 0.012
CVE-2023-49068
Apache DolphinScheduler: Information Leakage Vulnerability
Published 2023-11-27 · Modified
7.5EPSS 0.011
CVE-2025-62188
Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint.
Published 2026-04-09 · Analyzed
7.5EPSS 0.005
CVE-2023-49250
Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtil
Published 2024-02-20 · Analyzed
7.3EPSS 0.007
CVE-2020-13922
Apache DolphinScheduler (incubating) Permission vulnerability
Published 2021-01-11 · Modified
6.5EPSS 0.017
CVE-2022-26884
Apache DolphinScheduler exposes files without authentication
Published 2022-10-28 · Modified
6.5EPSS 0.016
CVE-2022-34662
Apache DolphinScheduler prior to 3.0.0 allows path traversal
Published 2022-11-01 · Modified
6.5EPSS 0.015
CVE-2023-50270
Apache DolphinScheduler: Session do not expire after password change
Published 2024-02-20 · Analyzed
6.5EPSS 0.013
CVE-2023-49620
Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for
Published 2023-11-30 · Modified
6.5EPSS 0.011
CVE-2026-47340
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Published 2026-06-17 · Modified
6.5EPSS 0.005
CVE-2026-42357
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Published 2026-06-17 · Modified
6.5EPSS 0.005
CVE-2025-62233
Apache DolphinScheduler: Deserialization of untrusted data in RPC
Published 2026-04-24 · Analyzed
6.3EPSS 0.005
CVE-2026-41280
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
Published 2026-06-17 · Analyzed
4.9EPSS 0.005
CVE-2023-25601
Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authentication
Published 2023-04-20 · Modified
4.3EPSS 0.011