Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-71896

DolphinScheduler user list authorization flaw exposes account information

Apache DolphinScheduler CVE-2026-71896 lets authenticated users retrieve other users' account information through the user list-all endpoint and enumerate accounts. Apache rates it critical. Fixed in 3.4.3. CISA-ADP CVSS 3.1 6.5. Not in CISA KEV. No public PoC.

CVSS
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Class
Info disclosure
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache DolphinScheduler
Affected
All versions before 3.4.3 (CNA range 0 to before 3.4.3).
Fixed
Apache DolphinScheduler 3.4.3 or later.
Published
8 Oct 2026
Updated
8 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-71896 is an authorization vulnerability in Apache DolphinScheduler, announced by the Apache DolphinScheduler project on 8 October 2026 on its mailing list and oss-security. It lets authenticated users retrieve other users' account information through the user list-all endpoint and enumerate accounts. The attacker must hold a valid DolphinScheduler account; Apache does not describe unauthenticated access.

Apache's advisory says the user list-all API endpoint fails to enforce the necessary authorization checks before returning user account information. Any authenticated user can therefore view account information they are not authorized to see. Apache says successful exploitation may expose sensitive user information and facilitate account enumeration. The advisory does not list which account fields are returned.

Apache rates the issue critical. Apache does not publish a CVSS score. CISA-ADP (shown on NVD) scores it CVSS 3.1 6.5 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. Apache labels the issue critical while the CISA-ADP score is 6.5 (Medium). ThreatWire keeps Apache's label for severity and the CISA-ADP number as the only published score. Apache CNA maps CWE-863 (Incorrect Authorization). Affected versions: All versions before 3.4.3 (CNA range 0 to before 3.4.3). Apache recommends upgrading to 3.4.3, which fixes the issue. The 3.4.3 release was published on GitHub on 6 September 2026. Apache credits n0mi1k and lemi9090 as finders.

The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none. ThreatWire found no public proof-of-concept repository, and Apache does not report exploitation. GitHub advisory GHSA-q59v-7f6x-gwrc is unreviewed and carries no score. NVD lists the record as Received, without its own analysis.

This CVE is one of six DolphinScheduler authorization issues disclosed together on 8 October 2026 (CVE-2026-66082, CVE-2026-66084, CVE-2026-66087, CVE-2026-71183, CVE-2026-71895 and CVE-2026-71896), all fixed in 3.4.3.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-71896