Apache · Dolphinscheduler · CVE-2026-82804
**Name of the Vulnerable Software and Affected Versions**
Apache DolphinScheduler versions prior to 3.4.3
**Description**
An authenticated user can achieve arbitrary command execution with the privileges of the DolphinScheduler service process. This occurs because the `scriptPath` parameter is incorporated into a `/bin/sh -c` command without sufficient neutralization of shell metacharacters, enabling shell command substitution. An attacker can exploit this by creating a resource with a filename containing shell command substitution syntax, such as $(...), and providing that path to the Alert Script plugin's `/test-send` endpoint.
**Recommendations**
Upgrade to version 3.4.3.