PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32966 Apache Software Foundation CVE debrief

Apache DolphinScheduler versions before 3.4.2 are vulnerable to a critical issue (CVSS 9.8) due to a missing authorization check in the DataSource API. This oversight allows for arbitrary data source metadata disclosure. The vulnerability, tracked as CVE-2026-32966, was made public on June 17, 2026. Users of affected versions are strongly advised to upgrade to version 3.4.2, which addresses this issue. The vulnerability's high CVSS score reflects its potential for significant impact, with attackers able to exploit it remotely without authentication. This issue is categorized under CWE-863, highlighting the need for robust authorization mechanisms in API design.

Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Organizations using Apache DolphinScheduler versions before 3.4.2 should prioritize upgrading to version 3.4.2 or later. This vulnerability's critical severity and potential for remote exploitation without authentication make it a high-risk issue for environments where DolphinScheduler is exposed to untrusted networks or users.

Technical summary

The CVE-2026-32966 vulnerability in Apache DolphinScheduler arises from a missing authorization check in the DataSource API. This API, intended for managing data sources, inadvertently allows unauthorized access to data source metadata. The issue is characterized by a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a high level of exploitability and potential impact. Specifically, attackers can exploit this vulnerability remotely without requiring any user interaction or authentication, potentially leading to the disclosure of sensitive metadata.

Defensive priority

High

Recommended defensive actions

  • Upgrade Apache DolphinScheduler to version 3.4.2 or later.
  • Implement robust authentication and authorization checks for all API endpoints.
  • Conduct regular security audits to identify and address potential vulnerabilities.
  • Limit exposure of DolphinScheduler to untrusted networks or users.
  • Monitor for suspicious activity related to the DataSource API.
  • Review and enhance API security design to prevent similar issues.
  • Apply security patches and updates promptly.

Evidence notes

The information provided is based on the CVE-2026-32966 record and related sources. The CVE was published on June 17, 2026, and last modified on the same day. The vulnerability affects Apache DolphinScheduler versions before 3.4.2. The CVSS score of 9.8 indicates a critical vulnerability. The CWE-863 classification emphasizes the issue of missing authorization.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-32966 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-32966

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-32966 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32966

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.