<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dolphinscheduler on CVE Alert &amp; Security Feed</title><link>https://cvealert.net/products/dolphinscheduler/</link><description>Recent content in Dolphinscheduler on CVE Alert &amp; Security Feed</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 17 Jun 2026 13:20:41 +0000</lastBuildDate><atom:link href="https://cvealert.net/products/dolphinscheduler/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-47340</title><link>https://cvealert.net/posts/cve-2026-47340/</link><pubDate>Wed, 17 Jun 2026 13:20:41 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-47340/</guid><description>Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.</description></item><item><title>CVE-2026-42357</title><link>https://cvealert.net/posts/cve-2026-42357/</link><pubDate>Wed, 17 Jun 2026 13:20:39 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-42357/</guid><description>Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.</description></item><item><title>CVE-2026-41280</title><link>https://cvealert.net/posts/cve-2026-41280/</link><pubDate>Wed, 17 Jun 2026 13:20:38 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-41280/</guid><description>Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.</description></item><item><title>CVE-2026-32966</title><link>https://cvealert.net/posts/cve-2026-32966/</link><pubDate>Wed, 17 Jun 2026 13:20:16 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-32966/</guid><description>DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.</description></item><item><title>CVE-2026-32967</title><link>https://cvealert.net/posts/cve-2026-32967/</link><pubDate>Wed, 17 Jun 2026 13:20:16 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-32967/</guid><description>Incorrect Authorization vulnerability of &lt;code&gt;/v2&lt;/code&gt; experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.</description></item></channel></rss>