
🐬 Apache DolphinScheduler has a CVSS 9.8 missing auth check in its DataSource API. No login needed to expose arbitrary data source metadata. Upgrade to 3.4.2 now. CVE-2026-32966 #Apache #infosec https://secalerts.co/vulnerability/CVE-2026-32966 https://t.co/RQ0QwWe4BN
Post summary
This tweet highlights a high‑severity vulnerability (CVSS 9.8) in Apache DolphinScheduler’s DataSource API that allows unauthenticated data exposure, and urges users to patch immediately by upgrading to version 3.4.2.
