Authorization Vulnerability in Apache DolphinScheduler Affects User Data Privacy
CVE-2026-71896
Currently unrated
What is CVE-2026-71896?
An authorization vulnerability in Apache DolphinScheduler exists that permits authenticated users to access and retrieve account information of other users through the /dolphinscheduler/users/list-all endpoint without the requisite permissions. This flaw arises because the endpoint does not enforce the necessary authorization checks, thus enabling unauthorized access to sensitive account details. Successful exploitation can not only lead to exposure of private user information but may also open avenues for account enumeration. To mitigate this risk, it is strongly recommended that users upgrade to version 3.4.3 or newer, where this issue has been addressed.
Affected Version(s)
Apache DolphinScheduler 0 < 3.4.3