PT-2026-102608 · Apache · Dolphinscheduler

·

CVE-2026-82804

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions prior to 3.4.3
Description An authenticated user can achieve arbitrary command execution with the privileges of the DolphinScheduler service process. This occurs because the scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, enabling shell command substitution. An attacker can exploit this by creating a resource with a filename containing shell command substitution syntax, such as $(...), and providing that path to the Alert Script plugin's /test-send endpoint.
Recommendations Upgrade to version 3.4.3.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82804

Affected Products

Dolphinscheduler