CVE-2026-47340
Description
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Summary dbcve.org
This is an broken access control vulnerability in Apache DolphinScheduler where authenticated users can access alert instances belonging to alert groups they do not have permission to view. The application fails to properly validate user permissions before returning alert instance data, allowing privilege escalation through unauthorized access to sensitive alert configurations.
Mitigation
Upgrade to Apache DolphinScheduler version 3.4.2 which contains the authorization fix for this vulnerability.