PT-2026-95484 · Azkaban · Azkaban

·

CVE-2026-93737

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Azkaban versions prior to 4.0.1
Description An authorization bypass exists in the fetchSchedule action of the ScheduleServlet endpoint. Authenticated users can retrieve schedule configurations for any project by providing arbitrary project and flow identifiers. This allows unauthorized access to sensitive information, including execution times, cron expressions, flow parameters, and notification email lists.
Recommendations Update Azkaban to a version later than 4.0.0. As a temporary mitigation, restrict access to the ScheduleServlet endpoint to authorized administrators only.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93737

Affected Products

Azkaban