CVE-2026-66083
Received Received - Intake

Information Disclosure in Apache DolphinScheduler

Vulnerability report for CVE-2026-66083, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache dolphinscheduler to 3.4.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Apache DolphinScheduler before version 3.4.3. The /datasources/unauth-datasource endpoint fails to enforce proper authorization checks. An authenticated user can access this endpoint to retrieve details about data sources they are not permitted to view, potentially exposing sensitive metadata and configuration details.

Detection Guidance

To detect this vulnerability, check if your Apache DolphinScheduler version is before 3.4.3. Run the command: curl -s http://<server>:<port>/datasources/unauth-datasource | grep -i "data source" to see if unauthorized data sources are exposed.

Impact Analysis

An attacker with valid credentials could exploit this flaw to gather unauthorized information about data sources, including configuration details. This may lead to further attacks, data leaks, or unauthorized access to sensitive systems depending on the exposed metadata.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data source configurations, potentially violating GDPR (data protection) or HIPAA (healthcare data privacy) by exposing confidential information. Compliance may be compromised if unauthorized data exposure occurs.

Mitigation Strategies

Upgrade Apache DolphinScheduler to version 3.4.3 or later immediately. Follow the official upgrade guide from Apache DolphinScheduler documentation to apply the patch.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66083. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart