CVE-2026-71895: Apache DolphinScheduler: Missing Authorization Checks Allow Non-Admin Users to Retrieve Kubernetes Credentials
DolphinScheduler before 3.4.3 lets non-admins retrieve Kubernetes kubeconfig credentials.
CVE-2026-71895 affects Apache DolphinScheduler 3.1.0 before 3.4.3. Authenticated non-admin users can retrieve Kubernetes configuration intended for administrators, including kubeconfig credentials that may allow direct authentication to the Kubernetes API outside DolphinScheduler. Apache rated the issue important, and no in-the-wild exploitation is reported.
- Non-admin users can retrieve administrator kubeconfig data.
- Exposed credentials may authenticate directly to the Kubernetes API.
- Affects DolphinScheduler 3.1.0 before 3.4.3; rated important.
Vulnerabilities mentionedAll →
- CVE-2026-718957.1—Missing auth in Apache DolphinScheduler leaks Kubernetes credentialspublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71895 | Missing auth in Apache DolphinScheduler leaks Kubernetes credentials Apache DolphinScheduler versions from 3.2.0 before 3.4.3 have a missing authorization check that lets an authenticated non-admin user retrieve Kubernetes configuration data reserved for administrator-managed cluster configuration. The user triggers this through DolphinScheduler while logged in; the returned kubeconfig includes credentials that can be used to authenticate directly to the Kubernetes API outside the product. What an attacker can do depends on those credentials: cluster-admin or broadly privileged service-account access may allow reading Kubernetes Secrets, creating pods, and establishing persistent cluster access. Organizations running an affected release that stores Kubernetes cluster configuration are in scope. No public proof of concept is known, the issue is not in CISA KEV, and CVSS is not yet scored. |
Posted by Wenjun Ruan on Oct 07 Severity: important Affected versions: - Apache DolphinScheduler 3.1.0 before 3.4.3 Description: An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The...
This source does not provide full text. Read it at seclists.org.