CVE-2026-71896: Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of User Account Information
DolphinScheduler before 3.4.3 lets authenticated users list other accounts without authorization.
Apache rated CVE-2026-71896 critical in DolphinScheduler before 3.4.3. The /dolphinscheduler/users/list-all endpoint does not enforce required authorization, letting an authenticated user retrieve other users' account information. The advisory does not report exploitation in the wild.