Improper access control in Apache DolphinScheduler - CVE-2026-47340
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to access alert instances associated with alert groups they do not have permission to access.
The vulnerability exists due to improper access control in the dolphinscheduler-api alert instance access functionality when handling requests for alert instances. A remote user can send a request for alert instances associated with unauthorized alert groups to access alert instances associated with alert groups they do not have permission to access.