Apache DolphinScheduler <3.4.3: /datasources auth bypass
CVE-2026-66083 Published on September 29, 2026

Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Vendor Advisory NVD

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-66083

Want to know whenever a new CVE is published for Apache DolphinScheduler? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache DolphinScheduler: