Sceawere

Vulnerability Detail

CVE-2026-71183UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DolphinScheduler Unauthorized Data Source Access

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
8h ago
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authenticated user without permission to access a data source can retrieve its connection details and credentials. Successful exploitation exposes sensitive data source information and may enable unauthorized access to the underlying databases using the disclosed credentials. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-08T09:16:42.037Z",
  "pubdate": "2026-10-08T09:16:42.037Z",
  "executiveSummary": "This vulnerability involves an improper authorization flaw within Apache DolphinScheduler that allows authenticated users to access sensitive data source configurations.\nThe vulnerability is categorized as an authorization bypass, enabling unauthorized exposure of metadata and connection credentials.\nAffected products include all versions of Apache DolphinScheduler prior to 3.4.3.\nThe risk implication is critical, as successful exploitation results in the unauthorized disclosure of database connection strings and plaintext credentials.\nExploitation requires an attacker to possess valid user credentials within the DolphinScheduler instance, but does not require administrative privileges.\nOnce unauthorized access to these sensitive credentials is obtained, an attacker can move laterally to the underlying database systems, potentially leading to full data compromise or unauthorized modification of external information assets.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper implementation of authorization checks within the /unauth-datasource and /authed-datasource endpoints of the Apache DolphinScheduler API.\nThese specific endpoints fail to perform server-side verification of user permissions regarding data source access, effectively treating all authenticated requests as authorized.\nThe vulnerable component is the data source management module, which handles the retrieval and display of metadata for connected database systems.\nThe attack flow commences when an authenticated user sends a GET request to the /unauth-datasource or /authed-datasource endpoints. Despite the user lacking the requisite permissions to view specific data sources, the application backend neglects to filter the response based on the user's role or object-level permissions.\nConsequently, the system returns a comprehensive JSON payload containing sensitive database connection details, including hostnames, usernames, and plaintext passwords associated with the data sources.\nThe exposure is not limited to metadata; it explicitly includes internal security credentials required to establish connections to external databases.\nFrom an exploitation perspective, an attacker does not need to bypass primary authentication; they merely need to leverage their session token to query these endpoints. Once the sensitive payload is returned, the attacker can extract the embedded database credentials.\nPost-exploitation impact involves the utilization of these disclosed credentials to access external databases directly, bypassing the security controls imposed by the DolphinScheduler application layer. This constitutes a significant escalation of privilege and a breach of data confidentiality for any downstream systems managed by the application.\nThis vulnerability persists in all environments where Apache DolphinScheduler versions below 3.4.3 are deployed, regardless of the underlying database infrastructure used by the software."
}
CVE-2026-71183: DolphinScheduler Unauthorized Data Source Access (HIGH Severity, CVSS: 7.1) | Sceawere