Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-66087

DolphinScheduler task instance stop/savepoint project authorization bypass

Apache DolphinScheduler CVE-2026-66087 lets an authenticated user stop or savepoint task instances in projects they are not authorized to access. Apache rates it moderate. Fixed in 3.4.3. No CVSS score published yet. Not in CISA KEV. No public PoC.

CVSS
Unknown
Vector
Not recorded
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache DolphinScheduler
Affected
All versions before 3.4.3 (CNA range 0 to before 3.4.3).
Fixed
Apache DolphinScheduler 3.4.3 or later.
Published
8 Oct 2026
Updated
8 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-66087 is an authorization vulnerability in Apache DolphinScheduler, announced by the Apache DolphinScheduler project on 8 October 2026 on its mailing list and oss-security. It lets an authenticated user stop or savepoint task instances in projects they are not authorized to access. The attacker must hold a valid DolphinScheduler account; Apache does not describe unauthenticated access.

Apache's advisory says authenticated users can operate on task instances in projects they are not authorized to access through the task instance stop and savepoint endpoints. The advisory is short and does not describe the root cause beyond the project authorization bypass. Apache CNA maps the issue to CWE-863 (Incorrect Authorization).

Apache rates the issue moderate. No CVSS score has been published by Apache, NVD or CISA-ADP at the time of writing. Apache CNA maps CWE-863 (Incorrect Authorization). Affected versions: All versions before 3.4.3 (CNA range 0 to before 3.4.3). Apache recommends upgrading to 3.4.3, which fixes the issue. The 3.4.3 release was published on GitHub on 6 September 2026. Apache credits Meng Qingwei, h1ei1, meifukun, yansong and Omar Mousa as finders.

The CVE is not in the CISA KEV catalog. CISA-ADP has not added an SSVC assessment yet. ThreatWire found no public proof-of-concept repository, and Apache does not report exploitation. GitHub advisory GHSA-8x8j-rj29-7qph is unreviewed and carries no score. NVD lists the record as Received, without its own analysis.

This CVE is one of six DolphinScheduler authorization issues disclosed together on 8 October 2026 (CVE-2026-66082, CVE-2026-66084, CVE-2026-66087, CVE-2026-71183, CVE-2026-71895 and CVE-2026-71896), all fixed in 3.4.3.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-66087