A notice published on September 24, 2026 reports an authorization flaw in Apache DolphinScheduler task-group APIs. Versions earlier than 3.4.3 are affected; upgrading is recommended.
A security notice published on September 24, 2026 describes CVE-2026-57590 in Apache DolphinScheduler, rated low severity.
According to the notice, task-group APIs do not correctly check whether an authenticated user may access the project associated with the target group. This could allow unauthorized operations across projects. Versions earlier than 3.4.3 are affected.
The stated recommendation is to upgrade to version 3.4.3. Check your installed version and consult the official release notes and original notice to confirm the scope and plan the upgrade according to your organization’s procedures.
If you use AI to study or apply the notice, do not submit credentials or unnecessary internal data. Rota Nacional can detect personal data before model execution and apply organizational policies for placeholders, removal, or blocking. Review usage metadata in the dashboard.