Unrated severityNVD Advisory· Published Jun 17, 2026
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CVE-2026-41280
Description
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
This issue affects Apache DolphinScheduler versions prior to 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes this issue.
Affected products
1- Range: <3.4.2
Patches
Vulnerability mechanics
Synthesis attempt was rejected by the grounding validator. Re-run pending.
References
1- lists.apache.org/thread/5bv1njp3lbbbj11y20td5yz1b4nmrtvwmitrevendor-advisory
News mentions
0No linked articles in our index yet.