Skip to content
Rota Nacional

Cyber ·

CVE-2026-66082: Apache DolphinScheduler allows cross-project authorization bypass in the API

Moderate-severity advisory: authenticated users of Apache DolphinScheduler before 3.4.3 can operate schedules, workflow definitions and task instances in other projects.

Published on the oss-sec feed on 7 October by Wenjun Ruan, advisory CVE-2026-66082 describes an authorization bypass in Apache DolphinScheduler, a data workflow orchestration platform. The stated severity is moderate, and the affected versions are those before 3.4.3. According to the text, users who are already authenticated can perform unauthorized operations on schedules, workflow definitions and task instances belonging to other projects. The stated cause is that the endpoints check permissions against the project code supplied in the request but do not confirm that the target resource actually belongs to that project. The source text is an automatic translation, so consult the original record before making decisions. For operators of the tool, the step indicated by the advisory's scope is to upgrade to version 3.4.3 or later and review permissions and access logs. Rota Nacional does not fix DolphinScheduler and is not part of that fix. If the team uses AI to study the advisory or plan remediation, do not paste tokens, passwords, full logs, internal project names or personal data. The platform detects CPF, CNPJ, e-mail, phone numbers and names before any model runs and applies the organization's policy, but the safest protection is not to send secrets at all.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free