CVE-2026-66084: Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpoint
DolphinScheduler before 3.4.3 lets authenticated users change task definitions in projects they do not own.
CVE-2026-66084 is a moderate project authorization bypass in Apache DolphinScheduler before 3.4.3. The task-definition with-upstream endpoint fails to verify that the task definition identified by code belongs to the supplied project, so authenticated users can modify definitions in projects they are not authorized to access. No active exploitation is described.
- CVE-2026-66084 affects Apache DolphinScheduler before 3.4.3.
- The with-upstream endpoint does not bind the definition to the project.
- Authenticated users can modify other projects' task definitions.
Vulnerabilities mentionedAll →
- CVE-2026-660848.1—Authorization Bypass in Apache DolphinScheduler Task Definitionspublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66084 | Authorization Bypass in Apache DolphinScheduler Task Definitions Apache DolphinScheduler before 3.4.3 has an incorrect-authorization flaw (CWE-863) in the task-definition with-upstream API. An authenticated user can supply a project code they are allowed to access together with a task-definition code from a different project, because the endpoint does not verify that the task belongs to the stated project. That lets the user modify the target task definition and its upstream dependencies, compromising workflow integrity and disrupting execution in projects they should not access. Every DolphinScheduler release before 3.4.3 is affected. No public proof of concept is known, the issue is not in CISA KEV, and CVSS has not yet been scored. Upgrade Apache DolphinScheduler to 3.4.3 or later. Until the upgrade is in place, restrict who can authenticate to the scheduler API and do not expose the service to the public internet. Review task-definition and upstream-dependency change history for edits by users who were not authorized for the affected project. |
Posted by Wenjun Ruan on Oct 07 Severity: moderate Affected versions: - Apache DolphinScheduler before 3.4.3 Description: An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the...
This source does not provide full text. Read it at seclists.org.