mediumCVSS 4.9Vulnerability
CVE-2026-41280
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
Properties
- severity
- medium
- summary
- Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
- epss_score
- 0.00437
- cvss_score
- 4.9
- ghsa_published
- 2026-06-17T18:35:50Z
- source_url
- https://github.com/advisories/GHSA-wh3w-v6gj-fqh2
- ghsa_updated
- 2026-06-18T14:32:56Z
- ghsa_id
- GHSA-wh3w-v6gj-fqh2
- cve_id
- CVE-2026-41280
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.36006
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
AFFECTS (1)
→[Software]maven/org.apache.dolphinscheduler:dolphinscheduler-api
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]maven/org.apache.dolphinscheduler:dolphinscheduler-api
Explore deeper with Ninja Signal's threat intelligence graph