Home

Description

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

PUBLISHED Reserved 2026-04-19 | Published 2026-06-17 | Updated 2026-06-17 | Assigner apache

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

Any version before 3.4.2
affected

Credits

Yicheng Yu(https://github.com/FHMTT) finder

References

www.openwall.com/lists/oss-security/2026/06/17/7

lists.apache.org/thread/5bv1njp3lbbbj11y20td5yz1b4nmrtvw vendor-advisory

cve.org (CVE-2026-41280)

nvd.nist.gov (CVE-2026-41280)

Download JSON