CVE-2026-66083: Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
DolphinScheduler before 3.4.3 can leak unauthorized data-source configuration and metadata to authenticated users.
Apache DolphinScheduler before 3.4.3 fails to enforce authorization on the /datasources/unauth-datasource endpoint. An authenticated user can retrieve information about data sources they are not allowed to access, including configuration and other sensitive metadata depending on returned fields. Apache rates the issue moderate. Exploitation is not mentioned.
- Affects Apache DolphinScheduler versions before 3.4.3.
- The /datasources/unauth-datasource endpoint skips authorization checks.
- Authenticated users may read configuration and metadata for unauthorized data sources.
- Apache rates the disclosure moderate; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-660836.5—Unauthorized data source disclosure in Apache DolphinSchedulerpublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66083 | Unauthorized data source disclosure in Apache DolphinScheduler Apache DolphinScheduler before 3.4.3 does not properly enforce authorization on the /datasources/unauth-datasource endpoint. An already authenticated user can call that endpoint and retrieve information about data sources they are not allowed to access, which can include configuration details and other sensitive metadata depending on the fields returned. The flaw is an authorization gap on a data-source lookup function (CWE-306), not a fully unauthenticated remote code execution issue, and it has not yet received a CVSS score. It affects deployments of Apache DolphinScheduler older than 3.4.3. There is no known public proof-of-concept and it is not listed in CISA KEV, so exploitation is none known. Upgrade Apache DolphinScheduler to 3.4.3 or later. Until then, limit which accounts can reach the API and review access logs for calls to /datasources/unauth-datasource, then rotate any credentials that may have been exposed in data-source configuration. |
Posted by Wenjun Ruan on Sep 29 Severity: moderate Affected versions: - Apache DolphinScheduler before 3.4.3 Description: The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue...
This source does not provide full text. Read it at seclists.org.