Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-66084

DolphinScheduler task definition with-upstream project authorization bypass

Apache DolphinScheduler CVE-2026-66084 lets an authenticated user modify task definitions and their upstream dependencies in projects they are not authorized to access. Apache rates it moderate. Fixed in 3.4.3. No CVSS score published yet. Not in CISA KEV. No public PoC.

CVSS
Unknown
Vector
Not recorded
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache DolphinScheduler
Affected
All versions before 3.4.3 (CNA range 0 to before 3.4.3).
Fixed
Apache DolphinScheduler 3.4.3 or later.
Published
8 Oct 2026
Updated
8 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-66084 is an authorization vulnerability in Apache DolphinScheduler, announced by the Apache DolphinScheduler project on 8 October 2026 on its mailing list and oss-security. It lets an authenticated user modify task definitions and their upstream dependencies in projects they are not authorized to access. The attacker must hold a valid DolphinScheduler account; Apache does not describe unauthenticated access.

Apache's advisory says the task definition "with-upstream" API endpoint does not verify that the task definition being changed belongs to the project named in the request. An authenticated user can pair a project they are allowed to access with a task definition from another project, bypass that project's access restrictions, and modify the target task definition and its upstream dependencies. Apache says this can compromise workflow integrity and disrupt task execution in unauthorized projects.

Apache rates the issue moderate. No CVSS score has been published by Apache, NVD or CISA-ADP at the time of writing. Apache CNA maps CWE-863 (Incorrect Authorization). Affected versions: All versions before 3.4.3 (CNA range 0 to before 3.4.3). Apache recommends upgrading to 3.4.3, which fixes the issue. The 3.4.3 release was published on GitHub on 6 September 2026. Apache credits Han, JunGyu, Thành Nguyễn, Yeonoh Park (CIS Lab, SeoulTech), h1ei1 and n0mi1k as finders.

The CVE is not in the CISA KEV catalog. CISA-ADP has not added an SSVC assessment yet. ThreatWire found no public proof-of-concept repository, and Apache does not report exploitation. GitHub advisory GHSA-26vh-p5jc-q2mg is unreviewed and carries no score. NVD lists the record as Received, without its own analysis.

This CVE is one of six DolphinScheduler authorization issues disclosed together on 8 October 2026 (CVE-2026-66082, CVE-2026-66084, CVE-2026-66087, CVE-2026-71183, CVE-2026-71895 and CVE-2026-71896), all fixed in 3.4.3.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-66084