Improper access control in Apache DolphinScheduler - CVE-2026-47340

 

Improper access control in Apache DolphinScheduler - CVE-2026-47340

Published: August 25, 2026


Vulnerability identifier: #VU145235
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47340
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access alert instances associated with alert groups they do not have permission to access.

The vulnerability exists due to improper access control in the dolphinscheduler-api alert instance access functionality when handling requests for alert instances. A remote user can send a request for alert instances associated with unauthorized alert groups to access alert instances associated with alert groups they do not have permission to access.


Affected software

Apache DolphinScheduler

How to mitigate CVE-2026-47340

Install security update from vendor's website.

Apache DolphinScheduler - update to 3.4.2

External References

Related Security Bulletins