Description
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint.



The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies.



This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Task Modification
Action: Immediate Patch
AI Analysis

Impact

An Apache DolphinScheduler vulnerability allows authenticated users to bypass project authorization and alter task definitions and their upstream dependencies via the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint does not verify that the referenced task belongs to the specified project, enabling a user to supply a task code from a different project and change its configuration. This breach can compromise workflow integrity and disrupt execution of tasks in projects where the user has no legitimate access.

Affected Systems

All installations of Apache DolphinScheduler prior to version 3.4.3 are affected. The vulnerability applies to the core project authorization logic of the DolphinScheduler platform.

Risk and Exploitability

While no CVSS or EPSS score is published, the flaw represents a high severity privilege escalation (CWE‑863). An attacker only needs an authenticated account to craft the request, meaning the attack surface is wide for users who have any login credentials. Because the flaw directly modifies configuration data, the potential for workflow disruption is significant, yet no exploitation evidence or KEV listing is currently available. The absence of an EPSS score suggests limited public exploitation at this time, but the capability remains.

Generated by OpenCVE AI on October 8, 2026 at 09:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading to Apache DolphinScheduler 3.4.3 or later.
  • If an immediate upgrade is not possible, restrict or disable the /with-upstream endpoint for users who are not project administrators and enforce role‑based access controls on task‑definition modifications.
  • Implement monitoring of task‑definition change logs and audit trails to detect unauthorized modifications and investigate alerts.

Generated by OpenCVE AI on October 8, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache dolphinscheduler
Vendors & Products Apache
Apache dolphinscheduler

Thu, 08 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Title Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpoint
Weaknesses CWE-863
References

Subscriptions

Apache Dolphinscheduler
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-08T09:16:26.347Z

Reserved: 2026-07-24T02:04:50.327Z

Link: CVE-2026-66084

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T09:16:41.783

Modified: 2026-10-08T09:16:41.783

Link: CVE-2026-66084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T09:30:16Z

Weaknesses