CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-66083: dolphinscheduler before 3.4.3 (exclusive); +1 more affected products

CVE-2026-66083. CVSS 3.1 base score 6.5 (MEDIUM, Source advisory). EPSS 0.00229 (percentile 0.12444), scored 2026-10-05.

Affected technology

dolphinscheduler · before 3.4.3 (exclusive)
apache

Apache DolphinScheduler · 0 to before 3.4.3
Apache Software Foundation

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. Source advisory’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-306
CCR priority
26.1 /100 (P4)
CVSS 3.1
6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N · Source advisory
EPSS
0.00229 · percentile 0.12444 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-66083.html