MEDIUM

CVE-2026-47340

Apache Dolphinscheduler 2026-06-17 CVSS v3.1
CVSS
6.5

Description

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Summary dbcve.org

This is an broken access control vulnerability in Apache DolphinScheduler where authenticated users can access alert instances belonging to alert groups they do not have permission to view. The application fails to properly validate user permissions before returning alert instance data, allowing privilege escalation through unauthorized access to sensitive alert configurations.

Mitigation

Upgrade to Apache DolphinScheduler version 3.4.2 which contains the authorization fix for this vulnerability.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

0.43%
Probability of exploitation in next 30 days
37.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE