CRITICAL9.8CVE-2026-32966Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
from 0, < 3.4.2
CRITICAL9.1CVE-2026-32967Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
from 0, < 3.4.2
MEDIUM6.5CVE-2026-47340Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
from 0, < 3.4.2
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM6.5Incorrect Default Permissions in Apache DolphinScheduler
from 0, < 1.3.2
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
from 0, < 3.4.2
MEDIUM4.3Apache DolphinScheduler's python gateway suffered from improper authentication
>= 3.0.0, < 3.1.2
—Apache DolphinScheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerability