CVE-2026-71183
DolphinScheduler data source authorization flaw discloses connection passwords
Apache DolphinScheduler CVE-2026-71183 lets an authenticated user retrieve connection details and passwords for data sources they are not authorized to access. Apache rates it important. Fixed in 3.4.3. CISA-ADP CVSS 3.1 7.1. Not in CISA KEV. No public PoC.
- CVSS
- 7.1
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Class
- Info disclosure
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Apache DolphinScheduler
- Affected
- All versions before 3.4.3 (CNA range 0 to before 3.4.3).
- Fixed
- Apache DolphinScheduler 3.4.3 or later.
- CWE
- CWE-863
- Published
- 8 Oct 2026
- Updated
- 8 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-71183 is an authorization vulnerability in Apache DolphinScheduler, announced by the Apache DolphinScheduler project on 8 October 2026 on its mailing list and oss-security. It lets an authenticated user retrieve connection details and passwords for data sources they are not authorized to access. The attacker must hold a valid DolphinScheduler account; Apache does not describe unauthenticated access.
Apache's advisory says the authorized and unauthorized data source listing endpoints fail to enforce data source access controls and return sensitive connection information, including data source passwords. An authenticated user without permission for a data source can therefore obtain its connection details and credentials. Apache says this may enable unauthorized access to the underlying databases with the disclosed credentials.
Apache rates the issue important. Apache does not publish a CVSS score. CISA-ADP (shown on NVD) scores it CVSS 3.1 7.1 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N. Apache CNA maps CWE-863 (Incorrect Authorization). Affected versions: All versions before 3.4.3 (CNA range 0 to before 3.4.3). Apache recommends upgrading to 3.4.3, which fixes the issue. The 3.4.3 release was published on GitHub on 6 September 2026. Apache credits Raphael Zanarelli as finders.
The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none. ThreatWire found no public proof-of-concept repository, and Apache does not report exploitation. GitHub advisory GHSA-g89m-rq7v-96f2 is unreviewed and carries no score. NVD lists the record as Received, without its own analysis.
This CVE is one of six DolphinScheduler authorization issues disclosed together on 8 October 2026 (CVE-2026-66082, CVE-2026-66084, CVE-2026-66087, CVE-2026-71183, CVE-2026-71895 and CVE-2026-71896), all fixed in 3.4.3.