CVE-2026-66084

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-08: 210-08
Referenced assets2 URLs
Full discourse2 posts
  • VulniPulse@vulnipulse

    CVE advisory: CVE-2026-66084 - apache: Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpoint. https://vulnipulse.com/advisories/apache-cve-2026-66084 #CVE #CyberSecurity #Apache #DolphinScheduler

    0000029
    13 followersView on X
  • zoomeyebot@zoomeyebot

    🚨 Apache DolphinScheduler 3.4.3 Fixes Six Authorization Flaws That Leak Passwords and Kubernetes Credentials Critical Vulnerability Alert! Apache DolphinScheduler is affected by CVE-2026-66084. 🔍 Identify Targets via ZoomEye: Search Dork: app="Apache DolphinScheduler" Exposure: 152.7k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgRG9scGhpblNjaGVkdWxlciI%3D #Apache #DolphinScheduler #CyberSecurity #ZoomEye

    0000035
    25 followersView on X

Explore more