CVE-2026-32966
CRITICAL
apache
dolphinscheduler
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Jun 17, 2026
Vendor
apache
Description
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.