Sceawere

Vulnerability Detail

CVE-2026-71896UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DolphinScheduler Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
8h ago
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view. Successful exploitation may expose sensitive user information and facilitate account enumeration. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-08T09:16:42.287Z",
  "pubdate": "2026-10-08T09:16:42.287Z",
  "executiveSummary": "An authorization vulnerability exists in Apache DolphinScheduler before version 3.4.3, allowing authenticated users to retrieve sensitive account information of other users without proper authorization. The security flaw is located within the `/dolphinscheduler/users/list-all` endpoint, which fails to enforce necessary permission checks before returning user records. Consequently, any authenticated user, regardless of their privilege level, can access this endpoint to view complete user account details.\nThe exploitation of this vulnerability requires only standard user authentication, making the barrier to entry relatively low. Successful exploitation results in unauthorized information disclosure and account enumeration. By accessing the complete list of platform users, an attacker can obtain sensitive metadata, map the user base, and leverage this data to plan targeted credential-stuffing or brute-force attacks. Organizations running vulnerable versions of Apache DolphinScheduler are advised to upgrade to version 3.4.3 immediately to remediate this security exposure.",
  "technicalDetails": "The vulnerability is situated within the API routing and controller logic of Apache DolphinScheduler, specifically involving the `/dolphinscheduler/users/list-all` endpoint. Under a secure role-based access control (RBAC) model, access to a global user directory is restricted to administrators. However, in affected versions prior to 3.4.3, the application fails to validate the privileges of the requesting user session before executing the query logic for this endpoint.\nThe attack flow proceeds through the following phases:\n1. Session Establishment: The attacker authenticates to the Apache DolphinScheduler instance using valid, low-privileged credentials.\n2. Request Generation: The attacker bypasses user interface controls and sends a direct HTTP request to the `/dolphinscheduler/users/list-all` endpoint.\n3. Server-Side Execution: The backend server processes the incoming request. Because it lacks backend authorization validation checks, it does not verify if the session initiator possesses administrative privileges.\n4. Information Retrieval: The application executes the database query to retrieve all user accounts and returns the complete dataset to the unauthorized client.\nThe root cause of this flaw is a Broken Function Level Authorization (BFLA) vulnerability. The application relies on client-side interface restrictions to hide administrative actions rather than verifying permission states on the server side. As a result, the endpoint trusts any authenticated session and returns sensitive user information.\nThe primary impact is the exposure of user metadata, which facilitates account enumeration. Armed with a list of valid usernames, an adversary can launch offline brute-force, password-spraying, or social engineering campaigns. Additionally, in environments where usernames are shared across multiple corporate systems, this exposure can assist in lateral movement across the broader network infrastructure."
}
CVE-2026-71896: DolphinScheduler Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere