MEDIUM 4.9 Maven
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
GHSA-wh3w-v6gj-fqh2 · CVE-2026-41280
Published · Modified
Description
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
This issue affects Apache DolphinScheduler versions prior to 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes this issue.
Ready to move
Start Securing
Free, no credit card | First findings in minutes