{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-57590", "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09", "state": "PUBLISHED", "assignerShortName": "apache", "dateReserved": "2026-06-25T01:50:27.496Z", "datePublished": "2026-09-24T09:13:45.800Z", "dateUpdated": "2026-09-24T17:07:41.930Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09", "shortName": "apache", "dateUpdated": "2026-09-24T09:13:45.800Z" }, "title": "Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations", "problemTypes": [ { "descriptions": [ { "description": "CWE-863 Incorrect Authorization", "lang": "en", "cweId": "CWE-863", "type": "CWE" } ] } ], "source": { "discovery": "UNKNOWN" }, "affected": [ { "vendor": "Apache Software Foundation", "product": "Apache DolphinScheduler", "packageURL": "pkg:maven/org.apache.dolphinscheduler/dolphinscheduler-api", "versions": [ { "status": "affected", "version": "0", "lessThan": "3.4.3", "versionType": "semver" } ], "defaultStatus": "unaffected", "collectionURL": "https://repo.maven.apache.org/maven2", "packageName": "org.apache.dolphinscheduler:dolphinscheduler-api" } ], "descriptions": [ { "value": "A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.\n\n\n\nThis issue affects Apache DolphinScheduler: before 3.4.3.\n\n\n\nUsers are recommended to upgrade to version 3.4.3, which fixes the issue.", "lang": "en", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.

This issue affects Apache DolphinScheduler: before 3.4.3.

Users are recommended to upgrade to version 3.4.3, which fixes the issue.

" } ] } ], "references": [ { "url": "https://lists.apache.org/thread/3ncvptkjw9h6s8mjxlwwo30bxxgol6ry", "tags": [ "vendor-advisory" ] } ], "metrics": [ { "other": { "type": "Textual description of severity", "content": { "text": "low" } }, "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "credits": [ { "lang": "en", "value": "Meng Qingwei", "type": "finder" }, { "lang": "en", "value": "Thành Nguyễn", "type": "finder" }, { "lang": "en", "value": "Yeonoh Park", "type": "finder" }, { "lang": "en", "value": "tonghuaroot", "type": "finder" }, { "lang": "en", "value": "George Chen", "type": "finder" } ], "x_generator": { "engine": "Vulnogram 1.0.3" } }, "adp": [ { "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 8.1, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-24T12:37:30.984797Z", "id": "CVE-2026-57590", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-24T12:37:41.951Z" } }, { "title": "CVE Program Container", "references": [ { "url": "http://www.openwall.com/lists/oss-security/2026/09/24/3" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2026-09-24T17:07:41.930Z" } } ] } }