Apache DolphinScheduler Auth Bypass /users/list-all before 3.4.3
CVE-2026-71896 Published on October 8, 2026

Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of User Account Information
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view. Successful exploitation may expose sensitive user information and facilitate account enumeration. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Vendor Advisory NVD

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2026-71896 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-71896

Want to know whenever a new CVE is published for Apache DolphinScheduler? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache DolphinScheduler: