Advisory CVE-2026-71183 describes an authorization flaw in Apache DolphinScheduler. According to the text, authenticated users can access information about data sources they should not be allowed to see, through the /unauth-datasource and /authed-datasource endpoints. These endpoints do not enforce the required access controls and return sensitive connection information. The severity is rated important and the affected versions are those before 3.4.3. The advisory was published on October 7, 2026 on the oss-sec feed. The available material is a machine translation and is truncated, so details beyond these are not confirmed here. To verify, consult the original advisory referenced in the oss-sec feed and the project's version documentation.
Cyber ·
CVE-2026-71183: Apache DolphinScheduler authorization flaw exposes data sources and passwords
Advisory published on October 7, 2026 on the oss-sec feed: authenticated users can obtain data source connection details without authorization in versions before 3.4.3 of Apache DolphinScheduler.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.