Authorization Misconfiguration in Apache DolphinScheduler Affects Data Security
CVE-2026-66083

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-66083?

The Apache DolphinScheduler has a vulnerability in the /datasources/unauth-datasource endpoint due to improper authorization enforcement. This flaw allows authenticated users to access detailed information about unauthorized data sources, including configuration details and sensitive metadata. To mitigate this risk, users are advised to upgrade to version 3.4.3, which addresses the authorization issue and enhances data security.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
meifukun
Mingsheng Lin
ThĂ nh Nguyá»…n
Raphael Zanarelli
geo-chen
.