Severity: moderate
Affected versions:
- Apache DolphinScheduler before 3.4.3
Description:
An authorization bypass vulnerability in Apache DolphinScheduler allows
authenticated users to modify task definitions in projects they are not
authorized to access through the
/dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream
endpoint.
The endpoint fails to verify that the task definition identified by code
belongs to the project specified by projectCode. An authenticated user can
supply the code of a project they are authorized to access together with a task
definition code from another project, bypassing project access restrictions and
modifying the target task definition and its upstream dependencies.
This vulnerability can compromise workflow integrity and disrupt task execution
in unauthorized projects.This issue affects Apache DolphinScheduler: before
3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Credit:
Han, JunGyu (finder)
Thành Nguyễn (finder)
Yeonoh Park @ CIS Lab, SeoulTech (finder)
h1ei1 (finder)
n0mi1k (finder)
References:
https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-66084