Sceawere
Vulnerability Detail
CVE-2026-71183UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DolphinScheduler Unauthorized Data Source Access
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 8h ago
- Vendor
- Apache Software Foundation
- Product
- Apache DolphinScheduler
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authenticated user without permission to access a data source can retrieve its connection details and credentials. Successful exploitation exposes sensitive data source information and may enable unauthorized access to the underlying databases using the disclosed credentials. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-08T09:16:42.037Z",
"pubdate": "2026-10-08T09:16:42.037Z",
"executiveSummary": "This vulnerability involves an improper authorization flaw within Apache DolphinScheduler that allows authenticated users to access sensitive data source configurations.\nThe vulnerability is categorized as an authorization bypass, enabling unauthorized exposure of metadata and connection credentials.\nAffected products include all versions of Apache DolphinScheduler prior to 3.4.3.\nThe risk implication is critical, as successful exploitation results in the unauthorized disclosure of database connection strings and plaintext credentials.\nExploitation requires an attacker to possess valid user credentials within the DolphinScheduler instance, but does not require administrative privileges.\nOnce unauthorized access to these sensitive credentials is obtained, an attacker can move laterally to the underlying database systems, potentially leading to full data compromise or unauthorized modification of external information assets.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of authorization checks within the /unauth-datasource and /authed-datasource endpoints of the Apache DolphinScheduler API.\nThese specific endpoints fail to perform server-side verification of user permissions regarding data source access, effectively treating all authenticated requests as authorized.\nThe vulnerable component is the data source management module, which handles the retrieval and display of metadata for connected database systems.\nThe attack flow commences when an authenticated user sends a GET request to the /unauth-datasource or /authed-datasource endpoints. Despite the user lacking the requisite permissions to view specific data sources, the application backend neglects to filter the response based on the user's role or object-level permissions.\nConsequently, the system returns a comprehensive JSON payload containing sensitive database connection details, including hostnames, usernames, and plaintext passwords associated with the data sources.\nThe exposure is not limited to metadata; it explicitly includes internal security credentials required to establish connections to external databases.\nFrom an exploitation perspective, an attacker does not need to bypass primary authentication; they merely need to leverage their session token to query these endpoints. Once the sensitive payload is returned, the attacker can extract the embedded database credentials.\nPost-exploitation impact involves the utilization of these disclosed credentials to access external databases directly, bypassing the security controls imposed by the DolphinScheduler application layer. This constitutes a significant escalation of privilege and a breach of data confidentiality for any downstream systems managed by the application.\nThis vulnerability persists in all environments where Apache DolphinScheduler versions below 3.4.3 are deployed, regardless of the underlying database infrastructure used by the software."
}