CVE-2026-32966
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
9.8
CRITICAL
CVSS 3.1
Description
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
How to fix CVE-2026-32966
To remediate CVE-2026-32966, upgrade the affected package to a fixed version below.
- Maven/org.apache.dolphinscheduler:dolphinscheduler-api—upgrade to 3.4.2 or later
Is CVE-2026-32966 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-32966.
Affected packages (1)
- from 0, < 3.4.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |