Back

MEDIUM

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

Published Jun 17, 2026

Description

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

This issue affects Apache DolphinScheduler versions prior to 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 17, 2026
Updated Jun 17, 2026
Reserved Apr 19, 2026
CISA Vulnrichment
Updated Jun 17, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Jun 17, 2026
Updated Jun 17, 2026
Exploited since n/a
EUVD-2026-37581 GHSA-WH3W-V6GJ-FQH2