Description
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions.



The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view.



Successful exploitation may expose sensitive user information and facilitate account enumeration.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of user account information
Action: Upgrade
AI Analysis

Impact

Apache DolphinScheduler suffers from an authorization bypass that allows any authenticated user to call the /dolphinscheduler/users/list-all endpoint and view account data belonging to other users. The missing permission check exposes usernames, email addresses, and role information, enabling administrator or user enumeration and providing a foothold for further attacks. This weakness is identified as missing authorization checks (CWE-863).

Affected Systems

Apache DolphinScheduler versions before 3.4.3 are affected. Users of the Apache Software Foundation’s DolphinScheduler product should confirm that they are running version 3.4.3 or later to include the fix.

Risk and Exploitability

The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog, indicating no known public exploitation. However, once an attacker has valid credentials, the flaw can be exploited simply by accessing the exposed endpoint, making the attack trivial for authenticated users. The impact is confined to confidentiality leakage of account information, and no additional conditions or advanced techniques are required.

Generated by OpenCVE AI on October 8, 2026 at 10:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache DolphinScheduler to version 3.4.3 or later
  • Configure role‑based access control so that only privileged users can access the /users/list-all endpoint
  • If an immediate upgrade is not possible, restrict or remove access to the endpoint through network ACLs or an API gateway to prevent unauthorized enumeration

Generated by OpenCVE AI on October 8, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache dolphinscheduler
Vendors & Products Apache
Apache dolphinscheduler

Thu, 08 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
References

Thu, 08 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view. Successful exploitation may expose sensitive user information and facilitate account enumeration. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of User Account Information
Weaknesses CWE-863
References

Subscriptions

Apache Dolphinscheduler
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-08T09:16:35.529Z

Reserved: 2026-08-08T01:20:46.471Z

Link: CVE-2026-71896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T09:16:42.287

Modified: 2026-10-08T10:17:10.470

Link: CVE-2026-71896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T10:30:16Z

Weaknesses