Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Meng Qingwei

#22551of 57,591
12.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-102616
4.3
2026-09-29
Apache · Dolphinscheduler · CVE-2026-81569
**Name of the Vulnerable Software and Affected Versions** Apache DolphinScheduler versions prior to 3.4.3 **Description** An improper authorization issue exists in the handling of sub-workflow tasks. An authenticated user without permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system fails to properly verify if the user has permission to execute the referenced workflow or access its project, allowing the bypass of project-level authorization controls. This may lead to the unauthorized execution of workflow tasks and access to resources or data available to the target workflow. **Recommendations** Upgrade to version 3.4.3.
PT-2026-97777
8.1
2026-09-24
Apache · Dolphinscheduler · CVE-2026-57590
**Name of the Vulnerable Software and Affected Versions** Apache DolphinScheduler versions prior to 3.4.3 **Description** A missing authorization issue exists in the Task Group APIs. The affected APIs fail to properly verify if an authenticated user possesses the necessary permissions to access the project linked to the target Task Group, potentially allowing unauthorized cross-project operations. **Recommendations** Upgrade to version 3.4.3.