CVE-2026-71183: Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Information and Passwords
DolphinScheduler before 3.4.3 discloses unauthorized data-source details and passwords.
CVE-2026-71183 is an authorization flaw in Apache DolphinScheduler before 3.4.3. Authenticated users can call /unauth-datasource and /authed-datasource and receive sensitive connection information, including passwords, for data sources they are not permitted to access. Apache rated the issue important; active exploitation is not described.
- /unauth-datasource and /authed-datasource skip access checks.
- Responses include connection details and passwords for unauthorized sources.
- Versions before 3.4.3 are affected; Apache rates it important.
Vulnerabilities mentionedAll →
- CVE-2026-711837.1—Missing authorization leaks data source passwords in DolphinSchedulerpublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71183 | Missing authorization leaks data source passwords in DolphinScheduler Apache DolphinScheduler before 3.4.3 has an incorrect-authorization flaw (CWE-863) in the /unauth-datasource and /authed-datasource endpoints. An authenticated user who is not permitted to use a data source can call those endpoints and receive sensitive connection information, including data source passwords. Those credentials can then be used to reach the underlying databases. The issue affects all DolphinScheduler releases before 3.4.3; 3.4.3 is the fixed version. It is not listed in CISA KEV, has no known public proof of concept, and exploitation in the wild is not known. Do: Upgrade Apache DolphinScheduler to 3.4.3 or later. Treat data-source connection details and passwords as exposed to any authenticated user, rotate those credentials, and review database access logs for unexpected use of the disclosed accounts. Until upgrade, restrict who can reach the scheduler UI and API. |
Posted by Wenjun Ruan on Oct 07 Severity: important Affected versions: - Apache DolphinScheduler before 3.4.3 Description: An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information,...
This source does not provide full text. Read it at seclists.org.