Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-71895

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
08/10/2026
Última modificación:
08/10/2026

Descripción

*** Pendiente de traducción *** An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler.<br /> <br /> <br /> <br /> The impact depends on the permissions granted to the disclosed credentials. If the kubeconfig provides cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods, and establish persistent access to the cluster.<br /> <br /> <br /> <br /> This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Impacto