CVE-2026-66082
Received Received - Intake

Authorization Bypass in Apache DolphinScheduler

Vulnerability report for CVE-2026-66082, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Apache Software Foundation

Description

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project. An authenticated user with the required permissions in one project can supply that project's code together with a resource identifier from another project, bypassing the target project's access restrictions. The affected endpoints include: * POST /projects/{projectCode}/schedules/{id}/online and /offline: Activate or deactivate workflow schedules in another project. * POST /projects/{projectCode}/workflow-definition/{code}/release: Change the ONLINE/OFFLINE state of workflow definitions in another project. Successful exploitation allows users to alter workflow availability and interfere with task execution in projects they are not authorized to access. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache DolphinScheduler 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authorization bypass vulnerability in Apache DolphinScheduler where authenticated users can perform unauthorized operations on workflow schedules, definitions, and tasks in other projects. The flaw occurs because endpoints check permissions using a project code but do not verify if the target resource belongs to that project. Users can manipulate project codes to access and modify resources in unauthorized projects.

Detection Guidance

To detect this vulnerability, monitor network traffic for suspicious API requests to the affected endpoints. Check for POST requests to /projects/{projectCode}/schedules/{id}/online, /offline, or /projects/{projectCode}/workflow-definition/{code}/release where the projectCode does not match the resource's actual project. Review logs for unauthorized changes to workflow schedules or definitions across projects.

Impact Analysis

If you use Apache DolphinScheduler versions before 3.4.3, an attacker with access to one project could alter workflow schedules, change workflow definitions, or interfere with task execution in other projects you manage. This could disrupt operations, cause data corruption, or lead to unauthorized changes in your workflows.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of sensitive workflows, potentially violating data integrity and access control requirements in GDPR and HIPAA. Unauthorized changes to workflows may result in non-compliance with these regulations, especially if they involve handling personal or health data.

Mitigation Strategies

Upgrade Apache DolphinScheduler to version 3.4.3 or later to fix the authorization bypass vulnerability affecting workflow schedules and definitions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66082. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart