Description
Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule configuration. Attackers can supply arbitrary project and flow identifiers to retrieve sensitive schedule details including execution times, cron expressions, flow parameters, and notification email lists without proper authorization.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

Azkaban versions up to and including 4.0.0 contain a flaw in the ScheduleServlet fetchSchedule action where project permission checks are omitted. The flaw allows any authenticated user to supply a project and flow identifier and retrieve the corresponding schedule configuration. The data revealed includes timestamps, cron expressions, flow parameters, and notification email lists, representing a moderate to high confidentiality breach.

Affected Systems

Affected products include the Azkaban project’s Azkaban component. The vulnerability is present in all releases through version 4.0.0. No higher‑version fix details were provided in the input, so users should verify whether their deployment is beyond 4.0.0.

Risk and Exploitability

The CVSS score of 7.1 indicates medium severity. The EPSS score of 0.307% indicates a very low probability of exploitation, and the vulnerability is not listed in KEV, suggesting limited real‑world usage. The flaw is exploitable over the network via HTTP requests to the ScheduleServlet endpoint and requires only authenticated access. The attack vector is inferred to be remote due to the web‑based nature of the servlet.

Generated by OpenCVE AI on September 19, 2026 at 17:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version of Azkaban that has the authorization check added (e.g., 4.0.1 or later).
  • If upgrade is delayed, restrict access to the ScheduleServlet endpoint by implementing role‑based access controls or firewall rules that block the fetchSchedule action for non‑privileged users.
  • Consider disabling or removing the fetchSchedule functionality from your deployment if it is not required.

Generated by OpenCVE AI on September 19, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Azkaban
Azkaban azkaban
Vendors & Products Azkaban
Azkaban azkaban

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule configuration. Attackers can supply arbitrary project and flow identifiers to retrieve sensitive schedule details including execution times, cron expressions, flow parameters, and notification email lists without proper authorization.
Title Azkaban through 4.0.0 Authorization Bypass via ScheduleServlet
First Time appeared Azkaban Project
Azkaban Project azkaban
Weaknesses CWE-862
CPEs cpe:2.3:a:azkaban_project:azkaban:*:*:*:*:*:*:*:*
Vendors & Products Azkaban Project
Azkaban Project azkaban
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Azkaban Azkaban
Azkaban Project Azkaban
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:50:31.810Z

Reserved: 2026-09-18T15:38:23.890Z

Link: CVE-2026-93737

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:53.256Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:16.340

Modified: 2026-09-22T20:29:59.707

Link: CVE-2026-93737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:01Z

Weaknesses