Authorization Misconfiguration in Apache DolphinScheduler Affects Data Security
CVE-2026-66083
Currently unrated
What is CVE-2026-66083?
The Apache DolphinScheduler has a vulnerability in the /datasources/unauth-datasource endpoint due to improper authorization enforcement. This flaw allows authenticated users to access detailed information about unauthorized data sources, including configuration details and sensitive metadata. To mitigate this risk, users are advised to upgrade to version 3.4.3, which addresses the authorization issue and enhances data security.
Affected Version(s)
Apache DolphinScheduler 0 < 3.4.3