---
id: CVE-2026-41280
title: >-
  Apache DolphinScheduler: Incorrect Authorization vulnerability allows users
  with system login privileges to delete task definitions in unauthorized
  projects
summary: >-
  Apache DolphinScheduler: Incorrect Authorization vulnerability allows users
  with system login privileges to delete task definitions in unauthorized
  projects
severity: medium
cvss: 4.9
cwe:
  - CWE-863
vendor: apache
product: 'org.apache.dolphinscheduler:dolphinscheduler-api'
ecosystem: maven
affected:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.2'
patched:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api 3.4.2'
published: '2026-06-17'
updated: '2026-06-18'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-wh3w-v6gj-fqh2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41280'
  - url: 'https://lists.apache.org/thread/5bv1njp3lbbbj11y20td5yz1b4nmrtvw'
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/17/7'
  - url: 'https://github.com/advisories/GHSA-wh3w-v6gj-fqh2'
tags:
  - ghsa
  - maven
epss: 0.00437
epssPercentile: 0.37491
ingestedAt: '2026-06-29T14:31:47.213Z'
---

## Overview

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

This issue affects Apache DolphinScheduler versions prior to 3.4.2. 

Users are recommended to upgrade to version 3.4.2, which fixes this issue.

## Affected packages

- `org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.2`

## Remediation

Upgrade to a patched release:

- `org.apache.dolphinscheduler:dolphinscheduler-api 3.4.2`
