Authorization Bypass in Apache DolphinScheduler Affects Project Integrity
CVE-2026-66084

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 October 2026

What is CVE-2026-66084?

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to alter task definitions in unauthorized projects via a specifically crafted endpoint. This occurs due to inadequate verification processes, enabling users to manipulate tasks associated with projects they are not permitted to access. Such actions threaten the integrity of workflows and potentially disrupt tasks across various projects. It is critical for users to upgrade to version 3.4.3 to address this vulnerability.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Han, JunGyu
ThĂ nh Nguyá»…n
Yeonoh Park @ CIS Lab, SeoulTech
h1ei1
n0mi1k
.