securityonline.info 8 Oct 2026, 04:04 UTC

Apache DolphinScheduler Fixes Six Flaws Exposing Credentials and Data

Apache DolphinScheduler Fixes Six Flaws Exposing Credentials and Data

APACHE DolphinScheduler has released version 3.4.3 to address six authorization flaws that could enable authenticated users to access sensitive data and, in some cases, credentials stored in Kubernetes. The vulnerabilities affect all releases prior to 3.4.3, with the Kubernetes credential flaw specifically impacting 3.2.0 and later.

Apache classifies the severity of the flaws as a mix of critical, important and moderate, but notes that none of the advisories report exploitation in the wild or a public PoC at the time of the fix.

The six CVEs share a common root cause: missing or broken permission checks for various APIs. CVE-2026-71895 lets non-admin users fetch Kubernetes configuration data, potentially exposing kubeconfig credentials that could permit authenticating to the Kubernetes API and, with broad cluster rights, reading Secrets, creating pods, and establishing persistent access. CVE-2026-71183 returns data source connection details, including passwords, to users without proper authorization.

CVE-2026-71896, rated critical, allows authenticated users to enumerate other users’ account information, exposing sensitive data and enabling account enumeration. The remaining three—CVE-2026-66082, CVE-2026-66084 and CVE-2026-66087—stem from a shared issue where permission checks against a project code do not verify that the targeted resource belongs to that project, enabling cross-project actions such as changing schedules, task definitions and running tasks in unintended projects. Practically, an attacker could stop a teammate’s task or rewrite upstream dependencies.

To mitigate, upgrade to 3.4.3 from the DolphinScheduler download page, and rotate Kubernetes and database credentials stored in DolphinScheduler after patching. It is also advised to review which accounts can log in, since all six flaws require a valid user.

View full article

Article by CyberSIXT