CVE-2026-57590: Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations
Apache DolphinScheduler before 3.4.3 has low-severity missing authorization in Task Group APIs, CVE-2026-57590.
Apache disclosed CVE-2026-57590, a low-severity missing-authorization flaw in DolphinScheduler Task Group APIs before version 3.4.3. The APIs do not properly check whether an authenticated user may access the project associated with a target Task Group, enabling unauthorized cross-project operations. Users are advised to upgrade to 3.4.3, and the report does not describe exploitation in the wild.
- CVE-2026-57590 affects Apache DolphinScheduler versions before 3.4.3.
- Task Group APIs fail to verify the caller's project permission.
- Apache rates the issue low and recommends upgrading to 3.4.3.
- The disclosure does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-575908.1—Missing Authorization in Apache DolphinScheduler Task Group APIspublished · Apache Software Foundation Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-57590 | Missing Authorization in Apache DolphinScheduler Task Group APIs Apache DolphinScheduler versions before 3.4.3 contain a broken access control flaw (CWE-863) in the Task Group APIs, which fail to verify that the authenticated user has permission on the project tied to the target task group. An attacker needs a valid account on the scheduler, but by referencing a task group belonging to another project they can perform actions on resources they are not authorized to access. Because the flaw violates confidentiality and integrity at high impact (CVSS 3.1: 8.1), a low-privileged user could read or modify other teams' task groups, which are used to control concurrent task-slot quotas in workflows. Any organization self-hosting DolphinScheduler on a release prior to 3.4.3 is affected. No public proof-of-concept exists and the issue is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is none known. |
Posted by Wenjun Ruan on Sep 24 Severity: low Affected versions: - Apache DolphinScheduler before 3.4.3 Description: A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3,...
This source does not provide full text. Read it at seclists.org.