SB20260825106 - Improper access control in Apache DolphinScheduler
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-23902)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to use tenants that are not defined on the platform during workflow execution.
The vulnerability exists due to improper access control in dolphinscheduler-api when executing workflows. A remote user can use an undefined tenant during workflow execution to use tenants that are not defined on the platform during workflow execution.
Exploitation requires valid system login permissions.
Remediation
Install update from vendor's website.