Improper access control in Apache DolphinScheduler - CVE-2026-23902

 

Improper access control in Apache DolphinScheduler - CVE-2026-23902

Published: August 25, 2026


Vulnerability identifier: #VU145330
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23902
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to use tenants that are not defined on the platform during workflow execution.

The vulnerability exists due to improper access control in dolphinscheduler-api when executing workflows. A remote user can use an undefined tenant during workflow execution to use tenants that are not defined on the platform during workflow execution.

Exploitation requires valid system login permissions.


Affected software

Apache DolphinScheduler

How to mitigate CVE-2026-23902

Install security update from vendor's website.

Apache DolphinScheduler - update to 3.4.1

External References

Related Security Bulletins