CVE-2026-47340

CVE-2026-47340: Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

Vendor Apache Software Foundation
Product Apache DolphinScheduler
Weakness CWE-200 · Info exposure
Published June 17, 2026
Last update June 17, 2026

CVSS base score

What the vulnerability does

Description

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Key dates

Disclosure timeline

June 17, 2026 CVE published