CVE-2026-42357: Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
This issue affects Apache DolphinScheduler versions prior to 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.dolphinscheduler:dolphinscheduler-apito a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42357?
The severity of CVE-2026-42357 is classified as medium with a CVSS score of 6.5.
How do I fix CVE-2026-42357?
To fix CVE-2026-42357, users should upgrade to Apache DolphinScheduler version 3.4.2 or later.
What systems are affected by CVE-2026-42357?
CVE-2026-42357 affects Apache DolphinScheduler versions prior to 3.4.2.
What type of vulnerability is CVE-2026-42357?
CVE-2026-42357 is categorized as an Incorrect Authorization vulnerability.
What impact does CVE-2026-42357 have on users?
CVE-2026-42357 allows unauthorized users to access workflow instance information from projects they do not have permission to access.