Improper access control in Apache DolphinScheduler - CVE-2026-23902
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to use tenants that are not defined on the platform during workflow execution.
The vulnerability exists due to improper access control in dolphinscheduler-api when executing workflows. A remote user can use an undefined tenant during workflow execution to use tenants that are not defined on the platform during workflow execution.
Exploitation requires valid system login permissions.