OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-57590

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in the Task Group APIs of Apache DolphinScheduler allows authenticated users to access projects without proper permission verification. This could lead to unauthorized access to sensitive project data, posing a significant risk to organizations using affected versions prior to 3.4.3. Users of Apache DolphinScheduler should prioritize upgrading to version 3.4.3 to mitigate this vulnerability.

CVE
CVE-2026-57590
Severity
HIGH
CVSS
8.1
EPSS
0.23%
Apache

Original NVD Description

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.