CVE-2026-41280
Undergoing Analysis Undergoing Analysis - In Progress
Incorrect Authorization in Apache DolphinScheduler Allows Task Deletion

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Apache Software Foundation

Description
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
apache dolphinscheduler to 3.4.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The provided information does not specify how this vulnerability impacts compliance with common standards and regulations such as GDPR or HIPAA.

Executive Summary

CVE-2026-41280 is an Incorrect Authorization vulnerability in Apache DolphinScheduler. It allows users who have system login privileges to delete task definitions in projects for which they are not authorized.

This issue affects versions of Apache DolphinScheduler prior to 3.4.2.

Impact Analysis

This vulnerability can lead to unauthorized deletion of task definitions within projects, potentially disrupting workflows and causing loss of important scheduled tasks.

Since users with system login privileges can delete tasks in projects they should not have access to, it may result in operational issues and data integrity problems.

The severity of this vulnerability is considered moderate.

Mitigation Strategies

To mitigate this vulnerability, users are recommended to upgrade Apache DolphinScheduler to version 3.4.2 or later, which contains the fix for this issue.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41280. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart