CVE-2026-71896: Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of User Account Information
DolphinScheduler before 3.4.3 lets authenticated users list other accounts without authorization.
Apache rated CVE-2026-71896 critical in DolphinScheduler before 3.4.3. The /dolphinscheduler/users/list-all endpoint does not enforce required authorization, letting an authenticated user retrieve other users' account information. The advisory does not report exploitation in the wild.
- Missing authorization on /dolphinscheduler/users/list-all.
- Authenticated users can read other users' account information.
- Apache rates it critical; versions before 3.4.3 are affected.
Vulnerabilities mentionedAll →
- CVE-2026-718966.5—Missing Authorization in Apache DolphinScheduler User Listpublished · Apache Software Foundation Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71896 | Missing Authorization in Apache DolphinScheduler User List Apache DolphinScheduler before 3.4.3 has a missing authorization check (CWE-863) on the /dolphinscheduler/users/list-all endpoint. Any authenticated user can call that endpoint and receive other users' account information without the permissions that should be required. The disclosed data can expose sensitive account details and support account enumeration, but the flaw does not by itself grant unauthenticated access or remote code execution. Organizations running DolphinScheduler versions earlier than 3.4.3 are affected. There is no known public proof of concept, and the issue is not listed in CISA KEV. Do: Upgrade Apache DolphinScheduler to version 3.4.3 or later. Until then, restrict network access to the web API (especially /dolphinscheduler/users/list-all) to trusted administrators and review access logs for unexpected calls to that endpoint by ordinary authenticated users. |
Posted by Wenjun Ruan on Oct 07 Severity: critical Affected versions: - Apache DolphinScheduler before 3.4.3 Description: An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an...
This source does not provide full text. Read it at seclists.org.