Authorization Bypass in Apache DolphinScheduler Affects Project Integrity
CVE-2026-66084
Currently unrated
What is CVE-2026-66084?
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to alter task definitions in unauthorized projects via a specifically crafted endpoint. This occurs due to inadequate verification processes, enabling users to manipulate tasks associated with projects they are not permitted to access. Such actions threaten the integrity of workflows and potentially disrupt tasks across various projects. It is critical for users to upgrade to version 3.4.3 to address this vulnerability.
Affected Version(s)
Apache DolphinScheduler 0 < 3.4.3