dolphinschedulerGHSA-72mv-wwvm-vgp5
Apache DolphinScheduler has an Incorrect Authorization Vulnerability
High8.1CVE-2026-23902 · Published Apr 24, 2026 · updated May 5, 2026
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1, which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 3.4.1 | 3.4.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- CVE-2026-23902
More dolphinscheduler advisories
All dolphinscheduler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 24 | Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability | Medium6.3 | 3.3.1 |
| Apr 9 | Apache DolphinScheduler vulnerable to sensitive information disclosure | High7.5 | 3.2.0 |
| Sep 92025 | Apache DolphinScheduler vulnerable to Alert Script Attack | High8.8 | 3.2.2 |
| Sep 32025 | Apache DolphinScheduler Incorrect Default Permissions Vulnerability | Low | 3.3.1 |
| Aug 122024 | Apache DolphinScheduler: Resource File Read And Write Vulnerability | High8.1 | 3.2.2 |
| Aug 122024 | Apache DolphinScheduler: RCE by arbitrary js execution | High8.8 | 3.2.2 |