PT-2026-34873 · Apache · Apache Dolphinscheduler

Jihang Yu

·

Published

2026-04-24

·

Updated

2026-04-28

·

CVE-2026-23902

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions prior to 3.4.1
Description An incorrect authorization issue allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution.
Recommendations Upgrade to version 3.4.1.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-23902
GHSA-72MV-WWVM-VGP5

Affected Products

Apache Dolphinscheduler