Index
Search
Search the public record. Drafts and scheduled notes are not included.
news
Apache DolphinScheduler 3.4.3 fixes six authorization flaws
On 8 October 2026 Apache disclosed six authorization CVEs in DolphinScheduler, all fixed in 3.4.3. They include kubeconfig credential exposure to non-admin users (CVE-2026-71895), data source password disclosure (CVE-2026-71183), user account disclosure (CVE-2026-71896) and three cross-project bypasses. All require an authenticated account. Not in CISA KEV. No public PoC.
Published 5h ago
CVE-2026-66082
DolphinScheduler cross-project schedule and workflow authorization bypass
Auth bypass
Published 10h ago
CVE-2026-66084
DolphinScheduler task definition with-upstream project authorization bypass
Auth bypass
Published 10h ago
CVE-2026-66087
DolphinScheduler task instance stop/savepoint project authorization bypass
Auth bypass
Published 10h ago
CVE-2026-71183
DolphinScheduler data source authorization flaw discloses connection passwords
Info disclosure
Published 10h ago
CVE-2026-71895
DolphinScheduler lets non-admin users retrieve Kubernetes credentials
Info disclosure
Published 10h ago
CVE-2026-71896
DolphinScheduler user list authorization flaw exposes account information
Info disclosure
Published 10h ago
CVE-2026-103007
Elasticsearch manage_roles scope bypass enables privilege escalation
Auth bypass
Published 2d ago