🔐 CVE Alert

CVE-2026-66083

UNKNOWN 0.0

Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

CWE CWE-306
Vendor apache software foundation
Product apache dolphinscheduler
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache dolphinscheduler

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache dolphinscheduler are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache DolphinScheduler
0 < 3.4.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/b6brfom0jmy9kdt40qrn6dq0x4v2wxdr openwall.com: http://www.openwall.com/lists/oss-security/2026/09/29/19

Credits

n0mi1k meifukun Mingsheng Lin Thành Nguyễn Raphael Zanarelli geo-chen