CVE-2026-47340Medium· 6.5▾ SunlitApache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.4%
0.4% → 0.4%
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.2Upgrade to a patched release:
org.apache.dolphinscheduler:dolphinscheduler-api 3.4.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2026-32966Critical· 9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVE-2026-32967Critical· 9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVE-2026-41280Medium· 4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CVE-2026-42357Medium· 6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
CVE-2026-65017Medium· 6.5Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments