Skip to content
Rota Nacional

Cyber ·

CVE-2026-71895: Apache DolphinScheduler exposes kubeconfig to non-administrator users

Important-severity advisory: authenticated users without administrator roles can access kubeconfig data containing Kubernetes credentials. Affected versions run from 3.1.0 up to before 3.4.3.

According to the text received from the oss-sec feed, published on October 7, 2026, Apache DolphinScheduler has an authorization flaw rated important. Authenticated users who are not administrators can obtain Kubernetes configuration data that should stay restricted to cluster configuration managed by administrators. The exposed kubeconfig data contains credentials that may allow direct authentication to the Kubernetes API, outside DolphinScheduler. Affected versions run from 3.1.0 up to versions before 3.4.3. The received text is an automatic translation and is truncated; to confirm details such as the fixed version and mitigation recommendations, consult the original advisory on seclists.org in the oss-sec list and the project's official documentation. For operators of DolphinScheduler, the practical steps are to check the installed version, review which authenticated users have access, and consider rotating cluster credentials that may have been exposed.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free