Junglewise Threat Intelligence

CVE-2026-47340: Apache DolphinScheduler incorrect authorization in alert instances

CVE-2026-47340 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Technologies: org.apache.dolphinscheduler:dolphinscheduler-api (Maven), Apache Software Foundation DolphinScheduler. Vendors: Maven, Apache Software Foundation.

Executive brief

Apache DolphinScheduler is a workflow orchestration platform used to manage and monitor complex data processing tasks. A security flaw allows logged-in users to view alert notifications and system alert instances that they are not authorized to see. This could lead to the exposure of sensitive operational data or internal system information to unauthorized personnel.

Technical details

An incorrect authorization vulnerability (CWE-200) exists in the Apache DolphinScheduler API. The root cause is a failure to properly validate user permissions when requesting alert instances, allowing an authenticated user to bypass intended access controls and view alerts associated with unauthorized alert groups. The attack is reachable over the network and requires low-privileged authentication but no user interaction. This vulnerability is resolved in version 3.4.2.

Affected products

  • Apache Software Foundation DolphinScheduler < 3.4.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory
  • 2026-06-17: patched: Fixed in version 3.4.2

References

Related threats