CVE-2026-23902
Apache DolphinScheduler has an Incorrect Authorization Vulnerability
8.1
HIGH
CVSS 3.1
EPSS 0.02%
Description
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1, which fixes this issue.
How to fix CVE-2026-23902
To remediate CVE-2026-23902, upgrade the affected package to a fixed version below.
- —upgrade to 3.4.1 or later
Is CVE-2026-23902 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.4.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |