Authorization Bypass Vulnerability in Apache DolphinScheduler
CVE-2026-66087

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 October 2026

What is CVE-2026-66087?

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to manipulate task instances within projects they lack permission to access. This issue can be exploited via specific API endpoints, letting unauthorized interactions with task instances occur, jeopardizing project security. It is crucial for users to upgrade to version 3.4.3 to resolve this vulnerability.

Affected Version(s)

Apache DolphinScheduler 0 < 3.4.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Meng Qingwei
h1ei1
meifukun
yansong
Omar Mousa — Red Team & Security Researcher
.