CVE-2026-71895
DolphinScheduler lets non-admin users retrieve Kubernetes credentials
Apache DolphinScheduler CVE-2026-71895 lets authenticated non-admin users retrieve administrator-managed Kubernetes configuration (kubeconfig) data that contains cluster credentials. Apache rates it important. Fixed in 3.4.3. CISA-ADP CVSS 3.1 7.1. Not in CISA KEV. No public PoC.
- CVSS
- 7.1
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Class
- Info disclosure
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Apache DolphinScheduler
- Affected
- Apache's advisory text says 3.2.0 before 3.4.3. The advisory header and the CVE record's structured version data say 3.1.0 before 3.4.3. Treat 3.1.x as potentially affected.
- Fixed
- Apache DolphinScheduler 3.4.3 or later.
- CWE
- CWE-862
- Published
- 8 Oct 2026
- Updated
- 8 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-71895 is an authorization vulnerability in Apache DolphinScheduler, announced by the Apache DolphinScheduler project on 8 October 2026 on its mailing list and oss-security. It lets authenticated non-admin users retrieve administrator-managed Kubernetes configuration (kubeconfig) data that contains cluster credentials. The attacker must hold a valid DolphinScheduler account; Apache does not describe unauthenticated access.
Apache's advisory says authenticated non-admin users can retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig contains credentials that may let a user authenticate directly to the Kubernetes API outside DolphinScheduler. Apache says the impact depends on the permissions of those credentials: with cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods and establish persistent access to the cluster. Apache does not say whether instances with no Kubernetes cluster configured are exposed; ThreatWire expects the risk to apply where administrators have stored cluster configuration.
Apache rates the issue important. Apache does not publish a CVSS score. CISA-ADP (shown on NVD) scores it CVSS 3.1 7.1 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N. CISA-ADP maps CWE-862 (Missing Authorization); the Apache CNA record carries no CWE. Affected versions: Apache's advisory text says 3.2.0 before 3.4.3. The advisory header and the CVE record's structured version data say 3.1.0 before 3.4.3. Treat 3.1.x as potentially affected. Apache recommends upgrading to 3.4.3, which fixes the issue. The 3.4.3 release was published on GitHub on 6 September 2026. Apache credits h1ei1, n0mi1k, Влад Рящиков, meifukun and Wanxin Yin as finders.
The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none. ThreatWire found no public proof-of-concept repository, and Apache does not report exploitation. GitHub advisory GHSA-vpj2-fvw3-8jgc is unreviewed and carries no score. NVD lists the record as Received, without its own analysis.
This CVE is one of six DolphinScheduler authorization issues disclosed together on 8 October 2026 (CVE-2026-66082, CVE-2026-66084, CVE-2026-66087, CVE-2026-71183, CVE-2026-71895 and CVE-2026-71896), all fixed in 3.4.3.