---
id: CVE-2026-71183
title: >-
  An authorization vulnerability in Apache DolphinScheduler allows authenticated
  users to obtain information about data sources they are not authorized to
  access through the /unauth-datasource and /authed-datasource endpoints.




  These end…
summary: >-
  An authorization vulnerability in Apache DolphinScheduler allows authenticated
  users to obtain information about data sources they are not authorized to
  access through the /unauth-datasource and /authed-datasource endpoints.




  These end…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-863
vendor: Apache Software Foundation
product: 'org.apache.dolphinscheduler:dolphinscheduler-api'
affected:
  - 'org.apache.dolphinscheduler:dolphinscheduler-api < 3.4.3'
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:17:18.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71183'
references:
  - url: 'https://lists.apache.org/thread.html/9g0fx2kdqv9nj20k759shhly3vpg96mw'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/10/08/4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T13:11:37.705178Z'
ingestedAt: '2026-10-08T09:24:18.356Z'
---

## Overview

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints.



These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authenticated user without permission to access a data source can retrieve its connection details and credentials.



Successful exploitation exposes sensitive data source information and may enable unauthorized access to the underlying databases using the disclosed credentials.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
