---
id: CVE-2026-42357
title: >-
  Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to
  access workflow instance information belonging to projects they do not have
  permission to access. 
summary: >-
  Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to
  access workflow instance information belonging to projects they do not have
  permission to access. 
severity: medium
cvss: 6.5
cwe:
  - CWE-863
vendor: apache
product: 'org.apache.dolphinscheduler:dolphinscheduler-api'
ecosystem: maven
affected:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.2'
patched:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api 3.4.2'
published: '2026-06-17'
updated: '2026-06-18'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-wv7f-c794-82v6'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42357'
  - url: 'https://lists.apache.org/thread/74l2rrz32w2chn7vz64313gk7ox5wjtr'
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/17/4'
  - url: 'https://github.com/advisories/GHSA-wv7f-c794-82v6'
tags:
  - ghsa
  - maven
epss: 0.00492
epssPercentile: 0.39608
ingestedAt: '2026-06-29T14:31:47.212Z'
---

## Overview

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

This issue affects Apache DolphinScheduler versions prior to 3.4.2.


Users are recommended to upgrade to version 3.4.2, which fixes this issue.

## Affected packages

- `org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.2`

## Remediation

Upgrade to a patched release:

- `org.apache.dolphinscheduler:dolphinscheduler-api 3.4.2`
