Incorrect authorization in Apache DolphinScheduler - CVE-2026-42357
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose workflow instance information belonging to projects they do not have permission to access.
The vulnerability exists due to improper access control in the dolphinscheduler-api when handling requests for workflow instance information. A remote user can send a crafted request to disclose workflow instance information belonging to projects they do not have permission to access.