Apache DolphinScheduler <2.0.6 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-26884. PoCs published by shoucheng3.
AI-analyzed exploit summary This repository appears to be a writeup or documentation for CVE-2022-26884, focusing on Apache DolphinScheduler. It includes README files and source code but lacks explicit exploit code or proof-of-concept for the vulnerability.
Description
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
Exploits (1)
nomisec
WRITEUP
by shoucheng3 · poc
https://github.com/shoucheng3/apache__dolphinscheduler_CVE-2022-26884_2-0-5
This repository appears to be a writeup or documentation for CVE-2022-26884, focusing on Apache DolphinScheduler. It includes README files and source code but lacks explicit exploit code or proof-of-concept for the vulnerability.
Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target:
Apache DolphinScheduler
No auth needed
Prerequisites:
Access to the vulnerable DolphinScheduler instance
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/10/28/2
Mailing List, Vendor Advisory
https://lists.apache.org/thread/xfdst5y4hnrm2ntmc5jzrgmw2htyyb9c
Scores
CVSS v3
6.5
EPSS
0.0161
EPSS Percentile
82.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Lab Environment
COMMUNITY
Community Lab
Details
CWE
CWE-22
Status
published
Products (2)
apache/dolphinscheduler
< 2.0.6
org.apache.dolphinscheduler/dolphinscheduler
0 - 2.0.6Maven
Published
Oct 28, 2022
Tracked Since
Feb 18, 2026