CVE-2026-32967: Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Incorrect Authorization vulnerability of /v2 experimental interface in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.dolphinscheduler:dolphinscheduler-apito a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32967?
The severity of CVE-2026-32967 is rated as critical with a CVSS score of 9.1.
How do I fix CVE-2026-32967?
To fix CVE-2026-32967, users should upgrade to Apache DolphinScheduler version 3.4.2 or later.
What type of vulnerability is CVE-2026-32967?
CVE-2026-32967 is an Incorrect Authorization vulnerability affecting the `/v2` experimental interface.
What impact does CVE-2026-32967 have?
CVE-2026-32967 could lead to unauthorized access to sensitive information due to the lack of permission checks.
Which versions of Apache DolphinScheduler are affected by CVE-2026-32967?
CVE-2026-32967 affects versions of Apache DolphinScheduler prior to 3.4.2.