Skip to content
Rota Nacional

Cyber ·

CVE-2026-66084: authorization bypass in Apache DolphinScheduler (with-upstream endpoint)

Published on the oss-sec feed by Wenjun Ruan on 7 October, the moderate-severity flaw lets authenticated users modify task definitions in projects they are not authorized to access. Versions before 3.4.3 are affected.

The advisory describes an authorization bypass in Apache DolphinScheduler. The problem sits in the endpoint /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream, used for task definitions. According to the original text, the endpoint does not verify whether the task definition identified by the code parameter belongs to the project given in the path. As a result, an authenticated user can change definitions in projects without authorization. The severity is rated moderate, and versions before 3.4.3 are affected. The text received is truncated, so no further technical details, exploitation information or fixes beyond the indicated version are available. For teams running DolphinScheduler, the verifiable step is to check the installed version, upgrade to 3.4.3 or later, and review the system's own audit logs for task definition changes made through this endpoint. If the team uses AI to study the advisory, do not paste project codes, user names, real internal endpoints or server names. Rota Nacional detects and handles personal data such as CPF, CNPJ, e-mail, phone and person names before any model runs, but internal technical identifiers must be replaced with placeholders manually.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free