PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66084 Apache Software Foundation CVE debrief

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects. Affected deployments should prioritize verification and upgrading to version 3.4.3.

Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Apache DolphinScheduler deployments should assess exposure and prioritize upgrading to version 3.4.3. Affected operators, platforms, and security teams should review compensating controls and monitor for unauthorized modifications to task definitions. Security teams should verify affected scope and ensure proper access controls are in place.

Why it matters

Defenders should care about CVE-2026-66084 because it allows authenticated users to bypass project access restrictions and modify task definitions in unauthorized projects, potentially disrupting workflow integrity and task execution.

  • Compromise of workflow integrity
  • Disruption of task execution in unauthorized projects
  • Potential for unauthorized modifications to task definitions
  • Verification of project access restrictions

Technical summary

The /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. This allows authenticated users to bypass project access restrictions and modify task definitions in unauthorized projects, potentially disrupting workflow integrity and task execution. The vulnerability affects Apache DolphinScheduler versions before 3.4.3 and can be mitigated by upgrading to version 3.4.3 or later. Defenders should prioritize verifying and upgrading to prevent unauthorized modifications to task definitions.

Defensive priority

Defenders should prioritize verifying and upgrading to version 3.4.3 of Apache DolphinScheduler to prevent unauthorized modifications to task definitions.

Recommended defensive actions

  • Verify and upgrade to version 3.4.3 of Apache DolphinScheduler
  • Restrict access to the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint
  • Monitor for unauthorized modifications to task definitions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability affects Apache DolphinScheduler versions before 3.4.3 and allows authenticated users to bypass project access restrictions through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. Evidence is limited to CVE and NVD details. Defenders should verify affected scope and upgrade to version 3.4.3.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66084 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66084

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66084 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66084

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.