CVE WATCH / VULNERABILITY DETAIL
CVE-2026-71896
MEDIUMCVSS 6.5NVD feed
Published 8 October 2026 · tracked since 8 October 2026
Description
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions.The endpoint fails to enforce the necessary authorization checks before returni
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107573 HIGH 7.8
- CVE-2026-107275 MEDIUM 6.8
- CVE-2026-93509 MEDIUM 6.5
- CVE-2026-104660 HIGH 7.8
- CVE-2026-104671 MEDIUM 5.3
- CVE-2026-105190 MEDIUM 5.3
- CVE-2026-103649 HIGH 7.5
- CVE-2026-103010 HIGH 7.8
- CVE-2026-103011 MEDIUM 6.5
- CVE-2026-103517 MEDIUM 5.3