Skip to content
Rota Nacional

Cyber ·

CVE-2026-71896: Apache DolphinScheduler exposes user account information

Security advisory on an authorization flaw in Apache DolphinScheduler before version 3.4.3, rated critical, that lets authenticated users obtain other users' account data.

The identifier CVE-2026-71896 was published on the oss-sec feed on October 7, 2026, for Apache DolphinScheduler, a task scheduling platform. According to the advisory, the issue is rated critical and affects versions before 3.4.3. It is an authorization flaw: the endpoint /dolphinscheduler/users/list-all does not enforce the required checks before returning user account information. As a result, any authenticated user lacking the necessary permission can obtain other people's account data. The report is attributed to Wenjun Ruan. The text we have is cut off where it describes the full consequence, so the exact scope of the impact should be confirmed in the original source. For operators of DolphinScheduler, the verifiable step is to check the installed version, upgrade to 3.4.3 or later, and review which accounts can reach this endpoint. This item is not about language model inference. If your team uses AI to study the advisory, do not paste real names, e-mails, account records or credentials into prompts. Use fictitious data or placeholders. The original is on the oss-sec feed, as referenced by the advisory.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free