
CVE-2026-23902: Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution https://www.openwall.com/lists/oss-security/2026/04/24/1 CVE-2025-62233: Apache DolphinScheduler: Deserialization of untrusted data in RPC https://www.openwall.com/lists/oss-security/2026/04/24/2
Post summary
Two Apache DolphinScheduler vulnerabilities are disclosed: one enabling use of undefined tenants in workflow execution and another involving insecure deserialization in RPC; no PoC, exploit, or patch information is provided.


