VulnSea

org.apache.dolphinscheduler:dolphinscheduler-api vulnerabilities

CVEs whose affected-version data names the org.apache.dolphinscheduler:dolphinscheduler-api package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-32966Critical· 9.8
3mo ago

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.39%via GHSA
CVE-2026-32967Critical· 9.1
3mo ago

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.34%via GHSA
CVE-2026-41280Medium· 4.9
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.44%via GHSA
CVE-2026-42357Medium· 6.5
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.31%via GHSA
CVE-2026-47340Medium· 6.5
3mo ago

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.43%via GHSA
org.apache.dolphinscheduler:dolphinscheduler-api vulnerabilities (CVEs) · VulnSea