Sceawere
Vulnerability Detail
CVE-2026-71895UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DolphinScheduler Unauthorized Kubeconfig Exposure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 8h ago
- Vendor
- Apache Software Foundation
- Product
- Apache DolphinScheduler
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclosed credentials. If the kubeconfig provides cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods, and establish persistent access to the cluster. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-08T09:16:42.167Z",
"pubdate": "2026-10-08T09:16:42.167Z",
"executiveSummary": "An improper authorization vulnerability exists in Apache DolphinScheduler, specifically affecting the cluster management configuration interface. This vulnerability allows authenticated non-admin users to bypass access control checks and retrieve sensitive Kubernetes configuration data (kubeconfig).\nThe exposure of kubeconfig files is a high-severity security risk, as these files typically contain cluster-wide credentials, including API tokens, client certificates, or service account tokens used by the application to orchestrate Kubernetes workloads.\nBy successfully exploiting this flaw, an attacker gains credentials that may permit direct, authenticated access to the Kubernetes API server, effectively bypassing the DolphinScheduler application's internal security perimeter. Depending on the privileges assigned to the compromised credentials, an attacker could achieve full cluster-admin control, leading to unauthorized secret exfiltration, malicious pod creation, and complete cluster compromise.\nThe vulnerability affects Apache DolphinScheduler versions 3.2.0 through 3.4.2. Successful exploitation requires an authenticated session within the application, but no administrative privileges are necessary. Users are strongly advised to update to version 3.4.3 to remediate this access control failure.",
"technicalDetails": "The vulnerability resides in the authorization logic governing the retrieval of Kubernetes configuration data within the Apache DolphinScheduler cluster management module. The application incorrectly validates the security context of the requesting user when accessing endpoints responsible for serving kubeconfig files.\nRoot cause analysis indicates a failure in the application's API authorization layer, where the endpoint exposed to the frontend/UI does not enforce the requirement for administrative privileges. Consequently, any authenticated session, regardless of the user's assigned role or permissions, can trigger the retrieval process for administrator-managed cluster configurations.\nThe exploitation flow begins with an authenticated attacker interacting with the vulnerable API endpoint responsible for exporting or viewing Kubernetes cluster metadata. Since the backend lacks a strict role-based access control (RBAC) check at the controller or service level, the application proceeds to serialize the sensitive kubeconfig object associated with the targeted cluster and returns the plaintext credentials—including certificates, keys, or tokens—directly to the attacker in the HTTP response.\nOnce the kubeconfig data is retrieved, the attacker can leverage standard Kubernetes CLI tools (kubectl) or direct REST API calls to the Kubernetes API server. By using the compromised credentials outside of the DolphinScheduler environment, the attacker effectively impersonates the identity established within the kubeconfig.\nThe post-exploitation impact is contingent upon the scope of the identity captured in the exposed file. If the kubeconfig is configured with broad ClusterRoleBindings or high-privilege ServiceAccount tokens, the attacker can move laterally from the application layer to the underlying container orchestration layer. This may facilitate the execution of arbitrary commands within pods, access to sensitive secrets stored as Kubernetes secrets, modification of cluster state, and the establishment of persistent backdoors via rogue pods or DaemonSets.\nThis vulnerability is present in Apache DolphinScheduler versions ranging from 3.2.0 to 3.4.2. The security flaw is mitigated in version 3.4.3 by implementing proper authorization checks to ensure that only authorized administrative users can access sensitive orchestration credentials."
}