PatchSiren cyber security CVE debrief
CVE-2026-66084 Apache Software Foundation CVE debrief
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects. Affected deployments should prioritize verification and upgrading to version 3.4.3.
- Vendor
- Apache Software Foundation
- Product
- Apache DolphinScheduler
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Apache DolphinScheduler deployments should assess exposure and prioritize upgrading to version 3.4.3. Affected operators, platforms, and security teams should review compensating controls and monitor for unauthorized modifications to task definitions. Security teams should verify affected scope and ensure proper access controls are in place.
Why it matters
Defenders should care about CVE-2026-66084 because it allows authenticated users to bypass project access restrictions and modify task definitions in unauthorized projects, potentially disrupting workflow integrity and task execution.
- Compromise of workflow integrity
- Disruption of task execution in unauthorized projects
- Potential for unauthorized modifications to task definitions
- Verification of project access restrictions
Technical summary
The /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. This allows authenticated users to bypass project access restrictions and modify task definitions in unauthorized projects, potentially disrupting workflow integrity and task execution. The vulnerability affects Apache DolphinScheduler versions before 3.4.3 and can be mitigated by upgrading to version 3.4.3 or later. Defenders should prioritize verifying and upgrading to prevent unauthorized modifications to task definitions.
Defensive priority
Defenders should prioritize verifying and upgrading to version 3.4.3 of Apache DolphinScheduler to prevent unauthorized modifications to task definitions.
Recommended defensive actions
- Verify and upgrade to version 3.4.3 of Apache DolphinScheduler
- Restrict access to the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint
- Monitor for unauthorized modifications to task definitions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability affects Apache DolphinScheduler versions before 3.4.3 and allows authenticated users to bypass project access restrictions through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. Evidence is limited to CVE and NVD details. Defenders should verify affected scope and upgrade to version 3.4.3.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66084 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66084
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66084 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66084
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpo
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/66xxx/CVE-2026-66084.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread.html/cn6v1m8pfnjn7rsqkq1xow8v63pw27w2
Supplemental source - vendor-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.