Skip to content
Rota Nacional

Cyber ·

CVE-2026-71183: Apache DolphinScheduler authorization flaw exposes data sources and passwords

Advisory published on October 7, 2026 on the oss-sec feed: authenticated users can obtain data source connection details without authorization in versions before 3.4.3 of Apache DolphinScheduler.

Advisory CVE-2026-71183 describes an authorization flaw in Apache DolphinScheduler. According to the text, authenticated users can access information about data sources they should not be allowed to see, through the /unauth-datasource and /authed-datasource endpoints. These endpoints do not enforce the required access controls and return sensitive connection information. The severity is rated important and the affected versions are those before 3.4.3. The advisory was published on October 7, 2026 on the oss-sec feed. The available material is a machine translation and is truncated, so details beyond these are not confirmed here. To verify, consult the original advisory referenced in the oss-sec feed and the project's version documentation.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free