Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-71183— Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Information and Passwords

Quick assessment

Affected
Apache Software Foundation Apache DolphinScheduler
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache DolphinScheduler 存在一个授权漏洞。攻击者可以通过 和 接口,以经过身份认证但无权限访问某些数据源的用户身份,获取这些数据源的敏感信息。 这些接口未能正确执行所需的数据源访问控制,从而返回了包括数据源密码在内的敏感连接信息。因此,任何经过身份认证但未被授权访问特定数据源的用户,均可以获取该数据源的连接详情和凭据。 成功利用此漏洞会导致数据源敏感信息泄露,并可能使攻击者能够使用泄露的凭据未经授权使用底层数据库。 该漏洞影响 Apache DolphinScheduler 3.4.3 之前

AI Predicted 7.5 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71183

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Information and Passwords
Source: CVE Program / CVE List V5
Vulnerability Description
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authenticated user without permission to access a data source can retrieve its connection details and credentials. Successful exploitation exposes sensitive data source information and may enable unauthorized access to the underlying databases using the disclosed credentials. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache DolphinScheduler 0 ~ 3.4.3 -

II. Public POCs for CVE-2026-71183

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71183

请登录查看更多情报信息。

Other References for CVE-2026-71183 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-08 · 6 CVEs total

CVE-2026-71896 Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of Use
CVE-2026-71895 Apache DolphinScheduler: Missing Authorization Checks Allow Non-Admin Users to Retrieve Ku
CVE-2026-66087 Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint
CVE-2026-66084 Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream
CVE-2026-66082 Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (sch

IV. Related Vulnerabilities

V. Comments for CVE-2026-71183

No comments yet


Leave a comment