CVE WATCH / VULNERABILITY DETAIL

CVE-2026-71896

MEDIUMCVSS 6.5NVD feed

Published 8 October 2026 · tracked since 8 October 2026

Description

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions.The endpoint fails to enforce the necessary authorization checks before returni

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-71896 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-71896

MEDIUMCVSS 6.5NVD feed

Published 8 October 2026 · tracked since 8 October 2026

Description

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions.The endpoint fails to enforce the necessary authorization checks before returni

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]