CVE-2026-32966: Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.dolphinscheduler:dolphinscheduler-apito a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
What is CVE-2026-32966?
CVE-2026-32966 is a critical vulnerability in Apache DolphinScheduler where the DataSource API lacks proper authorization checks, leading to potential data source metadata disclosure.
What is the severity of CVE-2026-32966?
CVE-2026-32966 has a critical severity rating of 9.8 on the CVSS scale.
How do I fix CVE-2026-32966?
To fix CVE-2026-32966, users should upgrade to Apache DolphinScheduler version 3.4.2 or later.
What could be exposed due to CVE-2026-32966?
CVE-2026-32966 could lead to arbitrary disclosure of sensitive data source metadata.
Which versions of Apache DolphinScheduler are affected by CVE-2026-32966?
All versions of Apache DolphinScheduler before 3.4.2 are affected by CVE-2026-32966.