Incorrect authorization in Apache DolphinScheduler - CVE-2026-41280
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to delete task definitions in unauthorized projects.
The vulnerability exists due to improper access control in the task definition deletion functionality when handling deletion requests for task definitions. A remote user can send a deletion request targeting task definitions in unauthorized projects to delete task definitions in unauthorized projects.