Authorization Bypass in Apache DolphinScheduler Affects Project Management Features
CVE-2026-66082
Currently unrated
What is CVE-2026-66082?
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized actions on various workflow components across different projects. The flaw resides in the permission checks of specific API endpoints, where the system incorrectly validates project ownership. An authenticated user can exploit this vulnerability by manipulating the project code and resource identifiers to gain access to workflow schedules, definitions, and task instances in projects outside their authorization scope. This may lead to altering workflow states and causing disruptions in task execution. Users are advised to upgrade to version 3.4.3 to mitigate this issue.
Affected Version(s)
Apache DolphinScheduler 0 < 3.4.3