CVE-2026-71896
DolphinScheduler user list authorization flaw exposes account information
Apache DolphinScheduler CVE-2026-71896 lets authenticated users retrieve other users' account information through the user list-all endpoint and enumerate accounts. Apache rates it critical. Fixed in 3.4.3. CISA-ADP CVSS 3.1 6.5. Not in CISA KEV. No public PoC.
- CVSS
- 6.5
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Class
- Info disclosure
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Apache DolphinScheduler
- Affected
- All versions before 3.4.3 (CNA range 0 to before 3.4.3).
- Fixed
- Apache DolphinScheduler 3.4.3 or later.
- CWE
- CWE-863
- Published
- 8 Oct 2026
- Updated
- 8 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-71896 is an authorization vulnerability in Apache DolphinScheduler, announced by the Apache DolphinScheduler project on 8 October 2026 on its mailing list and oss-security. It lets authenticated users retrieve other users' account information through the user list-all endpoint and enumerate accounts. The attacker must hold a valid DolphinScheduler account; Apache does not describe unauthenticated access.
Apache's advisory says the user list-all API endpoint fails to enforce the necessary authorization checks before returning user account information. Any authenticated user can therefore view account information they are not authorized to see. Apache says successful exploitation may expose sensitive user information and facilitate account enumeration. The advisory does not list which account fields are returned.
Apache rates the issue critical. Apache does not publish a CVSS score. CISA-ADP (shown on NVD) scores it CVSS 3.1 6.5 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. Apache labels the issue critical while the CISA-ADP score is 6.5 (Medium). ThreatWire keeps Apache's label for severity and the CISA-ADP number as the only published score. Apache CNA maps CWE-863 (Incorrect Authorization). Affected versions: All versions before 3.4.3 (CNA range 0 to before 3.4.3). Apache recommends upgrading to 3.4.3, which fixes the issue. The 3.4.3 release was published on GitHub on 6 September 2026. Apache credits n0mi1k and lemi9090 as finders.
The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none. ThreatWire found no public proof-of-concept repository, and Apache does not report exploitation. GitHub advisory GHSA-q59v-7f6x-gwrc is unreviewed and carries no score. NVD lists the record as Received, without its own analysis.
This CVE is one of six DolphinScheduler authorization issues disclosed together on 8 October 2026 (CVE-2026-66082, CVE-2026-66084, CVE-2026-66087, CVE-2026-71183, CVE-2026-71895 and CVE-2026-71896), all fixed in 3.4.3.