Description
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of data source metadata
Action: Immediate patch
AI Analysis

Impact

The /datasources/unauth-datasource endpoint in Apache DolphinScheduler does not enforce proper data source authorization, allowing an authenticated user to retrieve configuration details and other metadata for data sources they should not have access to. This flaw, identified as CWE-306, results in a confidentiality breach that could expose credentials, connection strings, or other sensitive configuration information. The impact is limited to the data sources visible through this endpoint but could assist an attacker in further compromising systems that use those data sources.

Affected Systems

All installations of Apache DolphinScheduler prior to version 3.4.3 are vulnerable. Any environment running an affected version and providing this endpoint is at risk, regardless of the number of users or the network environment.

Risk and Exploitability

No CVSS score is available for this issue, and the EPSS score is not provided; it is not listed in the CISA KEV catalog. An attacker must first authenticate to the DolphinScheduler instance and then invoke the vulnerable endpoint. Because the flaw depends on possession of valid credentials, the primary attack vector is insider or compromised legitimate user access. While active exploitation has not been reported, the potential for data exposure makes this a moderate to high risk for organizations with sensitive data source configurations.

Generated by OpenCVE AI on September 29, 2026 at 17:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache DolphinScheduler to version 3.4.3 or later to apply the vendor‑provided fix.
  • Restrict access to the /datasources/unauth-datasource endpoint by configuring authentication and authorization policies or by blocking the endpoint through a firewall or API gateway so that only privileged users can invoke it.
  • Disable the endpoint or remove sensitive fields from the returned payload through configuration changes if an immediate upgrade is not feasible.

Generated by OpenCVE AI on September 29, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
References

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
Weaknesses CWE-306
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T15:08:39.560Z

Reserved: 2026-07-24T02:02:07.591Z

Link: CVE-2026-66083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T12:17:10.967

Modified: 2026-09-29T16:17:09.337

Link: CVE-2026-66083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:15:08Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function