Apache DolphinScheduler 3.4.3 fixes six authorization flaws
Apache DolphinScheduler before 3.4.3 has six authorization bugs letting authenticated users reach other projects' data, credentials, and accounts.
On 8 October 2026, oss-security published six Apache DolphinScheduler advisories, all fixed in 3.4.3 and none describing exploitation in the wild. CVE-2026-66082, CVE-2026-66084, and CVE-2026-66087 are moderate project authorization bypasses: authenticated users can change schedules, workflows, and task instances, modify task definitions via the with-upstream endpoint, or stop and savepoint tasks in projects they do not own, because checks trust a supplied project identifier without confirming the resource belongs to it. CVE-2026-71183, rated important, lets authenticated users call /unauth-datasource and /authed-datasource and receive connection details and passwords for unauthorized data sources. CVE-2026-71895, also rated important and affecting 3.1.0 before 3.4.3, lets non-admin users retrieve administrator Kubernetes kubeconfig credentials that may authenticate directly to the Kubernetes API. CVE-2026-71896, rated critical, leaves /dolphinscheduler/users/list-all without required authorization so an authenticated user can list other users' account information. The reports agree on the 3.4.3 fix and the lack of reported exploitation; only CVE-2026-71895 gives a lower affected bound of 3.1.0, while the others say versions before 3.4.3.
- Six Apache DolphinScheduler authorization flaws, published on oss-security on 2026-10-08, are fixed in 3.4.3; none of the advisories reports in-the-wild exploitation.
- CVE-2026-66082 (moderate, before 3.4.3): schedule, workflow, and task-instance APIs check the supplied projectCode but do not verify that the target resource belongs to that project.
- CVE-2026-66084 (moderate, before 3.4.3): the task-definition with-upstream endpoint does not bind a definition code to the supplied project, so authenticated users can modify other projects' task definitions.
- CVE-2026-66087 (moderate, before 3.4.3): task-instance stop and savepoint endpoints let authenticated users stop or savepoint tasks in projects they are not authorized to access.
- CVE-2026-71183 (important, before 3.4.3): /unauth-datasource and /authed-datasource return connection details and passwords for data sources the caller is not permitted to access.
- CVE-2026-71895 (important): DolphinScheduler 3.1.0 before 3.4.3 lets authenticated non-admins retrieve administrator kubeconfig credentials that may authenticate directly to the Kubernetes API.
- CVE-2026-71896 (critical, before 3.4.3): /dolphinscheduler/users/list-all does not enforce authorization, so an authenticated user can retrieve other users' account information.
Coverage timelineoldest first · each row is one article
- · 23h agoCVE-2026-66082: Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (schedule / workflow)
oss-security· 46
DolphinScheduler before 3.4.3 allows cross-project changes to schedules, workflows, and task instances.
- · 23h agoCVE-2026-66084: Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpoint
oss-security· 41
DolphinScheduler before 3.4.3 lets authenticated users change task definitions in projects they do not own.
- · 23h ago
Vulnerabilities in this storyAll →
- CVE-2026-660848.1—Authorization Bypass in Apache DolphinScheduler Task Definitionspublished · Apache DolphinScheduler+4 related
- CVE-2026-718966.5—Missing Authorization in Apache DolphinScheduler User Listpublished · Apache Software Foundation Apache DolphinScheduler
| CVE | Vulnerability |
|---|