Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <078dfccd-3aa4-a145-4600-81e2881feb19@apache.org>
Date: Thu, 24 Sep 2026 08:55:47 +0000
From: Wenjun Ruan <wenjun@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-57590: Apache DolphinScheduler: Missing Authorization in
 Task Group APIs Allows Unauthorized Cross-Project Operations 

Severity: low 

Affected versions:

- Apache DolphinScheduler before 3.4.3

Description:

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Credit:

Meng Qingwei (finder)
Thành Nguyễn (finder)
Yeonoh Park (finder)
tonghuaroot (finder)
George Chen (finder)

References:

https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-57590

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.