Description
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-09-24
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized cross-project access through Task Group APIs
Action: Immediate Patch
AI Analysis

Impact

A missing authorization check in the Task Group APIs of Apache DolphinScheduler allows an authenticated user to perform operations on task groups belonging to projects they do not own. This flaw enables an attacker to manipulate, delete, or create tasks across projects, compromising the integrity and confidentiality of job schedules. The weakness is classified as CWE‑863, indicating improper authorization controls.

Affected Systems

The vulnerability affects installations of Apache DolphinScheduler supplied by the Apache Software Foundation that are running a version prior to 3.4.3. Any deployment using 3.x before that release is exposed unless remedial configuration changes are applied.

Risk and Exploitability

Because the flaw is related to a lack of authorization verification, any user who can authenticate to the system can exploit it without additional privileges. No publicly available exploit is reported, but the absence of a CVSS score and EPSS data does not diminish the high potential impact noted by the missing access control. The vulnerability is not listed in the CISA KEV catalog at this time. The primary attack vector is by issuing legitimate API requests that target a task group in another project, bypassing project membership checks. Organizations without the patch remain at risk of unauthorized cross‑project task manipulation.

Generated by OpenCVE AI on September 24, 2026 at 10:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache DolphinScheduler 3.4.3 or later, which includes the authorization fix.
  • Review and reinforce role‑based access controls for all Task Group API endpoints, ensuring project membership checks are enforced.
  • Audit existing task groups for cross‑project exposure and revoke or revise permissions as necessary.

Generated by OpenCVE AI on September 24, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
References

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-24T17:07:41.930Z

Reserved: 2026-06-25T01:50:27.496Z

Link: CVE-2026-57590

cve-icon Vulnrichment

Updated: 2026-09-24T12:36:38.303Z

cve-icon NVD

Status : Received

Published: 2026-09-24T10:17:38.010

Modified: 2026-09-24T18:17:15.273

Link: CVE-2026-57590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T10:30:18Z

Weaknesses