According to the text received from the oss-sec feed, published on October 7, 2026, Apache DolphinScheduler has an authorization flaw rated important. Authenticated users who are not administrators can obtain Kubernetes configuration data that should stay restricted to cluster configuration managed by administrators. The exposed kubeconfig data contains credentials that may allow direct authentication to the Kubernetes API, outside DolphinScheduler. Affected versions run from 3.1.0 up to versions before 3.4.3. The received text is an automatic translation and is truncated; to confirm details such as the fixed version and mitigation recommendations, consult the original advisory on seclists.org in the oss-sec list and the project's official documentation. For operators of DolphinScheduler, the practical steps are to check the installed version, review which authenticated users have access, and consider rotating cluster credentials that may have been exposed.
Cyber ·
CVE-2026-71895: Apache DolphinScheduler exposes kubeconfig to non-administrator users
Important-severity advisory: authenticated users without administrator roles can access kubeconfig data containing Kubernetes credentials. Affected versions run from 3.1.0 up to before 3.4.3.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.