CVE-2026-66082: Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (schedule / workflow)
DolphinScheduler before 3.4.3 allows cross-project changes to schedules, workflows, and task instances.
CVE-2026-66082 is a moderate authorization bypass in Apache DolphinScheduler before 3.4.3. Authenticated users can operate on workflow schedules, workflow definitions, and task instances in other projects because affected endpoints check the supplied projectCode but do not verify that the target resource belongs to that project. Exploitation in the wild is not reported.
- CVE-2026-66082 is moderate and fixed in DolphinScheduler 3.4.3.
- Schedule, workflow, and task-instance APIs trust projectCode alone.
- Authenticated users can act on resources in other projects.
Vulnerabilities mentionedAll →
- CVE-2026-660826.5—Cross-project authorization bypass in Apache DolphinSchedulerpublished · Apache DolphinScheduler
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66082 | Cross-project authorization bypass in Apache DolphinScheduler Apache DolphinScheduler before 3.4.3 has an incorrect-authorization flaw (CWE-863) in several project APIs. Authenticated users who already have the needed rights in one project can send that project's projectCode together with a schedule, workflow-definition, or task-instance identifier from a different project, because the endpoints check permission only against the supplied project code and do not confirm the resource belongs to it. That lets them turn schedules on or off and change workflow definitions between ONLINE and OFFLINE in projects they are not allowed to access, disrupting workflow availability and task execution. Only deployments running versions before 3.4.3 are affected, and the fix is in 3.4.3. There is no known public proof of concept and no report of exploitation in the wild. |
Posted by Wenjun Ruan on Oct 07 Severity: moderate Affected versions: - Apache DolphinScheduler before 3.4.3 Description: An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project....
This source does not provide full text. Read it at seclists.org.