CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache.
CVE
CVE-2026-32966
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%
Apache
Original NVD Description
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)