Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
news
Apache DolphinScheduler 3.4.3 fixes six authorization flaws
On 8 October 2026 Apache disclosed six authorization CVEs in DolphinScheduler, all fixed in 3.4.3. They include kubeconfig credential exposure to non-admin users (CVE-2026-71895), data source password disclosure (CVE-2026-71183), user account disclosure (CVE-2026-71896) and three cross-project bypasses. All require an authenticated account. Not in CISA KEV. No public PoC.
Published 5h ago
HighNo PoC
CVE-2026-71895
DolphinScheduler lets non-admin users retrieve Kubernetes credentials
Info disclosure
Published 10h ago