Authorization Bypass in Apache DolphinScheduler Affects Project Management Features
CVE-2026-66082

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 October 2026

What is CVE-2026-66082?

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized actions on various workflow components across different projects. The flaw resides in the permission checks of specific API endpoints, where the system incorrectly validates project ownership. An authenticated user can exploit this vulnerability by manipulating the project code and resource identifiers to gain access to workflow schedules, definitions, and task instances in projects outside their authorization scope. This may lead to altering workflow states and causing disruptions in task execution. Users are advised to upgrade to version 3.4.3 to mitigate this issue.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aisle Research
Meng Qingwei
Yeonoh Park @ CIS Lab, SeoulTech
tonghuaroot
meifukun
ThĂ nh Nguyá»…n
.