CVE-2026-66087: Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint Endpoint
DolphinScheduler before 3.4.3 lets authenticated users stop or savepoint tasks in unauthorized projects.
CVE-2026-66087 is a moderate authorization bypass in Apache DolphinScheduler before 3.4.3. Authenticated users can stop or savepoint task instances in projects they are not authorized to access through the task-instance stop and savepoint endpoints. The disclosure does not report in-the-wild exploitation.
- CVE-2026-66087 is rated moderate and fixed in 3.4.3.
- Stop and savepoint endpoints skip project authorization checks.
- An authenticated user is required; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-660878.1—Authorization bypass in Apache DolphinScheduler task APIspublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66087 | Authorization bypass in Apache DolphinScheduler task APIs Apache DolphinScheduler before 3.4.3 has an authorization bypass (CWE-863) on task-instance stop and savepoint APIs. An authenticated user can call /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop or the matching savepoint endpoint for a project they are not allowed to access and still operate that task instance. The impact is unauthorized control of other projects’ running tasks, including stopping them or triggering a savepoint, which can disrupt scheduled data workflows. Any organization running an affected DolphinScheduler release is in scope; the issue is fixed in 3.4.3. There is no known public proof-of-concept and no report of in-the-wild exploitation, and the flaw is not listed in CISA KEV. |
Posted by Wenjun Ruan on Oct 07 Severity: moderate Affected versions: - Apache DolphinScheduler before 3.4.3 Description: An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This...
This source does not provide full text. Read it at seclists.org.