---
id: CVE-2026-66083
title: >-
  The /datasources/unauth-datasource endpoint does not properly enforce data
  source authorization
summary: >-
  The /datasources/unauth-datasource endpoint does not properly enforce data
  source authorization. An authenticated user can invoke this endpoint to obtain
  information about data sources they are not authorized to access. This may
  expose d…
severity: none
cwe:
  - CWE-306
vendor: Apache Software Foundation
product: 'org.apache.dolphinscheduler:dolphinscheduler-api'
affected:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.3'
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T12:17:10.967'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66083'
references:
  - url: 'https://lists.apache.org/thread/b6brfom0jmy9kdt40qrn6dq0x4v2wxdr'
    label: security@apache.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T12:33:37.294Z'
---

## Overview

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
