Missing Authorization Vulnerability in Apache DolphinScheduler Task Group APIs
CVE-2026-57590

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 September 2026

What is CVE-2026-57590?

A vulnerability in the Task Group APIs of Apache DolphinScheduler allows attackers to potentially access project data by bypassing proper authorization checks. This flaw occurs when the authenticated user is not adequately verified for access permissions related to the targeted Task Group, leaving the application susceptible to unauthorized actions. It is essential for users of earlier versions to upgrade to 3.4.3 to mitigate this security issue and safeguard their project data.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Meng Qingwei
ThĂ nh Nguyá»…n
Yeonoh Park
tonghuaroot
George Chen
.