SB20260825106 - Improper access control in Apache DolphinScheduler



SB20260825106 - Improper access control in Apache DolphinScheduler

Published: August 25, 2026

Security Bulletin ID SB20260825106
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-23902)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to use tenants that are not defined on the platform during workflow execution.

The vulnerability exists due to improper access control in dolphinscheduler-api when executing workflows. A remote user can use an undefined tenant during workflow execution to use tenants that are not defined on the platform during workflow execution.

Exploitation requires valid system login permissions.


Remediation

Install update from vendor's website.