CVE-2026-66083
Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
| CWE | CWE-306 |
| Vendor | apache software foundation |
| Product | apache dolphinscheduler |
| Published | Sep 29, 2026 |
| Last Updated | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache dolphinscheduler
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache dolphinscheduler are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache DolphinScheduler
0 < 3.4.3
References
Credits
n0mi1k meifukun Mingsheng Lin Thành Nguyễn Raphael Zanarelli geo-chen