TL;DR
The Apache Software Foundation has fixed six Apache DolphinScheduler vulnerabilities in version 3.4.3. All six are missing or broken authorization checks that logged-in users can abuse. The worst can expose data source passwords and Kubernetes credentials.
Route critical Apache CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
DolphinScheduler is an open-source platform for scheduling data workflows. It often holds credentials for databases and compute clusters. As a result, a low-privileged account could reach far beyond its own projects. Apache rates one of the six flaws critical, two important and three moderate. The advisories do not report any exploitation in the wild or a public proof-of-concept.
How the Attacks Work
Credential Leaks
CVE-2026-71895 lets non-admin users fetch Kubernetes configuration data. According to Apache, the exposed kubeconfig “contains credentials that may allow users to authenticate directly to the Kubernetes API.” With broad cluster rights, an attacker “may read Kubernetes Secrets, create pods, and establish persistent access.” Similarly, CVE-2026-71183 returns data source connection details, “including data source passwords,” to users without access.
User Data Exposure
CVE-2026-71896, rated critical, lets any authenticated user list other users’ account information. Apache warns this “may expose sensitive user information and facilitate account enumeration.”
Cross-Project Bypasses
The other three bugs, CVE-2026-66082, CVE-2026-66084 and CVE-2026-66087, share one root cause. Several API endpoints check permissions against a project code but do not confirm the target belongs to that project. A user can pair their own project code with another project’s resource ID. This lets them change schedules, task definitions and running tasks in projects they cannot access. For instance, an attacker could stop another team’s task or rewrite its upstream dependencies.
Affected Versions
Most of these Apache DolphinScheduler vulnerabilities affect all releases before 3.4.3. The Kubernetes credential flaw affects 3.2.0 and later.
Patch and Mitigation Steps
Upgrade to version 3.4.3, available from the DolphinScheduler 3.4.3 download page. After patching, rotate any Kubernetes and database credentials stored in DolphinScheduler. Also review which accounts can log in, since all of these Apache DolphinScheduler vulnerabilities require a valid user.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!