CVE-2026-42357

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
References
Link Resource
https://lists.apache.org/thread/74l2rrz32w2chn7vz64313gk7ox5wjtr Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/06/17/4 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*

History

17 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 13:20

Updated : 2026-06-17 17:16


NVD link : CVE-2026-42357

Mitre link : CVE-2026-42357

CVE.ORG link : CVE-2026-42357


JSON object : View

Products Affected

apache

  • dolphinscheduler
CWE
CWE-863

Incorrect Authorization