Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1.  Users are recommended to upgrade to version 3.4.1, which fixes this issue.
History

Fri, 24 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Apr 2026 12:30:00 +0000

Type Values Removed Values Added
References

Fri, 24 Apr 2026 11:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1.  Users are recommended to upgrade to version 3.4.1, which fixes this issue.
Title Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution.
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-04-24T18:33:34.025Z

Reserved: 2026-01-18T04:07:20.514Z

Link: CVE-2026-23902

cve-icon Vulnrichment

Updated: 2026-04-24T11:28:42.712Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-24T12:17:06.453

Modified: 2026-04-24T19:17:01.113

Link: CVE-2026-23902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.