Authorization Vulnerability in Apache DolphinScheduler Affects User Data Privacy
CVE-2026-71896

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 October 2026

What is CVE-2026-71896?

An authorization vulnerability in Apache DolphinScheduler exists that permits authenticated users to access and retrieve account information of other users through the /dolphinscheduler/users/list-all endpoint without the requisite permissions. This flaw arises because the endpoint does not enforce the necessary authorization checks, thus enabling unauthorized access to sensitive account details. Successful exploitation can not only lead to exposure of private user information but may also open avenues for account enumeration. To mitigate this risk, it is strongly recommended that users upgrade to version 3.4.3 or newer, where this issue has been addressed.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
lemi9090
.