mediumCVSS 4.9Vulnerability

CVE-2026-41280

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Properties

severity
medium
summary
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
epss_score
0.00437
cvss_score
4.9
ghsa_published
2026-06-17T18:35:50Z
source_url
https://github.com/advisories/GHSA-wh3w-v6gj-fqh2
ghsa_updated
2026-06-18T14:32:56Z
ghsa_id
GHSA-wh3w-v6gj-fqh2
cve_id
CVE-2026-41280
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
false
epss_percentile
0.36006

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS (1)

[Software]maven/org.apache.dolphinscheduler:dolphinscheduler-api

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]maven/org.apache.dolphinscheduler:dolphinscheduler-api

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-41280 (CVSS 4.9) — Ninja Signal Threat Intelligence | Ninja Signal