
CVE advisory: CVE-2026-66084 - apache: Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpoint. https://vulnipulse.com/advisories/apache-cve-2026-66084 #CVE #CyberSecurity #Apache #DolphinScheduler
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE advisory: CVE-2026-66084 - apache: Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpoint. https://vulnipulse.com/advisories/apache-cve-2026-66084 #CVE #CyberSecurity #Apache #DolphinScheduler

🚨 Apache DolphinScheduler 3.4.3 Fixes Six Authorization Flaws That Leak Passwords and Kubernetes Credentials Critical Vulnerability Alert! Apache DolphinScheduler is affected by CVE-2026-66084. 🔍 Identify Targets via ZoomEye: Search Dork: app="Apache DolphinScheduler" Exposure: 152.7k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgRG9scGhpblNjaGVkdWxlciI%3D #Apache #DolphinScheduler #CyberSecurity #ZoomEye