Home

Description

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

PUBLISHED Reserved 2026-04-26 | Published 2026-06-17 | Updated 2026-06-17 | Assigner apache

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

Any version before 3.4.1
affected

Credits

Yicheng Yu(https://github.com/FHMTT) finder

References

www.openwall.com/lists/oss-security/2026/06/17/4

lists.apache.org/thread/74l2rrz32w2chn7vz64313gk7ox5wjtr vendor-advisory

cve.org (CVE-2026-42357)

nvd.nist.gov (CVE-2026-42357)

Download JSON