Sceawere
Vulnerability Detail
CVE-2026-71896UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DolphinScheduler Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 8h ago
- Vendor
- Apache Software Foundation
- Product
- Apache DolphinScheduler
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view. Successful exploitation may expose sensitive user information and facilitate account enumeration. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T09:16:42.287Z",
"pubdate": "2026-10-08T09:16:42.287Z",
"executiveSummary": "An authorization vulnerability exists in Apache DolphinScheduler before version 3.4.3, allowing authenticated users to retrieve sensitive account information of other users without proper authorization. The security flaw is located within the `/dolphinscheduler/users/list-all` endpoint, which fails to enforce necessary permission checks before returning user records. Consequently, any authenticated user, regardless of their privilege level, can access this endpoint to view complete user account details.\nThe exploitation of this vulnerability requires only standard user authentication, making the barrier to entry relatively low. Successful exploitation results in unauthorized information disclosure and account enumeration. By accessing the complete list of platform users, an attacker can obtain sensitive metadata, map the user base, and leverage this data to plan targeted credential-stuffing or brute-force attacks. Organizations running vulnerable versions of Apache DolphinScheduler are advised to upgrade to version 3.4.3 immediately to remediate this security exposure.",
"technicalDetails": "The vulnerability is situated within the API routing and controller logic of Apache DolphinScheduler, specifically involving the `/dolphinscheduler/users/list-all` endpoint. Under a secure role-based access control (RBAC) model, access to a global user directory is restricted to administrators. However, in affected versions prior to 3.4.3, the application fails to validate the privileges of the requesting user session before executing the query logic for this endpoint.\nThe attack flow proceeds through the following phases:\n1. Session Establishment: The attacker authenticates to the Apache DolphinScheduler instance using valid, low-privileged credentials.\n2. Request Generation: The attacker bypasses user interface controls and sends a direct HTTP request to the `/dolphinscheduler/users/list-all` endpoint.\n3. Server-Side Execution: The backend server processes the incoming request. Because it lacks backend authorization validation checks, it does not verify if the session initiator possesses administrative privileges.\n4. Information Retrieval: The application executes the database query to retrieve all user accounts and returns the complete dataset to the unauthorized client.\nThe root cause of this flaw is a Broken Function Level Authorization (BFLA) vulnerability. The application relies on client-side interface restrictions to hide administrative actions rather than verifying permission states on the server side. As a result, the endpoint trusts any authenticated session and returns sensitive user information.\nThe primary impact is the exposure of user metadata, which facilitates account enumeration. Armed with a list of valid usernames, an adversary can launch offline brute-force, password-spraying, or social engineering campaigns. Additionally, in environments where usernames are shared across multiple corporate systems, this exposure can assist in lateral movement across the broader network infrastructure."
}