Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-66082

DolphinScheduler cross-project schedule and workflow authorization bypass

Apache DolphinScheduler CVE-2026-66082 lets an authenticated user with permissions in one project bring workflow schedules online or offline and change the release state of workflow definitions in other projects. Apache rates it moderate. Fixed in 3.4.3. No CVSS score published yet. Not in CISA KEV. No public PoC.

CVSS
Unknown
Vector
Not recorded
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache DolphinScheduler
Affected
All versions before 3.4.3 (CNA range 0 to before 3.4.3).
Fixed
Apache DolphinScheduler 3.4.3 or later.
Published
8 Oct 2026
Updated
8 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-66082 is an authorization vulnerability in Apache DolphinScheduler, announced by the Apache DolphinScheduler project on 8 October 2026 on its mailing list and oss-security. It lets an authenticated user with permissions in one project bring workflow schedules online or offline and change the release state of workflow definitions in other projects. The attacker must hold a valid DolphinScheduler account; Apache does not describe unauthenticated access.

Apache's advisory says the affected schedule and workflow-definition endpoints check permissions against the project code supplied in the request but do not verify that the target schedule or workflow definition belongs to that project. An authenticated user who holds the required permissions in one project can therefore act on resources in another project. Apache lists two operations: activating or deactivating workflow schedules, and changing the ONLINE/OFFLINE release state of workflow definitions. The advisory also mentions interference with task instances. Apache says successful exploitation lets users alter workflow availability and interfere with task execution in projects they are not authorized to access.

Apache rates the issue moderate. No CVSS score has been published by Apache, NVD or CISA-ADP at the time of writing. Apache CNA maps CWE-863 (Incorrect Authorization). Affected versions: All versions before 3.4.3 (CNA range 0 to before 3.4.3). Apache recommends upgrading to 3.4.3, which fixes the issue. The 3.4.3 release was published on GitHub on 6 September 2026. Apache credits Aisle Research, Meng Qingwei, Yeonoh Park (CIS Lab, SeoulTech), tonghuaroot, meifukun and Thành Nguyễn as finders.

The CVE is not in the CISA KEV catalog. CISA-ADP has not added an SSVC assessment yet. ThreatWire found no public proof-of-concept repository, and Apache does not report exploitation. GitHub advisory GHSA-r995-5488-jh52 is unreviewed and carries no score. NVD lists the record as Received, without its own analysis.

This CVE is one of six DolphinScheduler authorization issues disclosed together on 8 October 2026 (CVE-2026-66082, CVE-2026-66084, CVE-2026-66087, CVE-2026-71183, CVE-2026-71895 and CVE-2026-71896), all fixed in 3.4.3.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-66082