According to an automatic translation of an advisory posted to the oss-sec list on October 7 by Wenjun Ruan, CVE-2026-66087 is an authorization bypass flaw in Apache DolphinScheduler. It affects versions before 3.4.3 and is rated moderate. Authenticated users can operate task instances in projects they are not authorized to access, through the task instance stop and savepoint endpoints. The source text is short and ends incompletely, so the original English advisory should be consulted before any decision. To verify, find the advisory in the public oss-sec archive using the CVE identifier and check the date, severity and list of affected versions. Then check which DolphinScheduler version your organization runs and follow the project's official upgrade guidance. This record does not describe an exploit or a test procedure.
Cyber ·
CVE-2026-66087: authorization bypass in task instance stop and savepoint endpoints in Apache DolphinScheduler
Moderate-severity advisory for Apache DolphinScheduler: authenticated users can stop task instances and create savepoints in projects they are not authorized to access. Versions before 3.4.3 are affected.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.