---
id: CVE-2026-57590
title: >-
  A missing authorization vulnerability exists in the Task Group APIs of Apache
  DolphinScheduler
summary: >-
  A missing authorization vulnerability exists in the Task Group APIs of Apache
  DolphinScheduler. The affected APIs do not properly verify whether the
  authenticated user has permission to access the project associated with the
  target Task …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-863
vendor: Apache Software Foundation
product: 'org.apache.dolphinscheduler:dolphinscheduler-api'
affected:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.3'
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T19:36:39.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57590'
references:
  - url: 'https://lists.apache.org/thread/3ncvptkjw9h6s8mjxlwwo30bxxgol6ry'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/24/3'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00229
epssPercentile: 0.12229
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T12:37:30.984797Z'
ingestedAt: '2026-09-24T09:40:50.748Z'
---

## Overview

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
