Stats Digest Feeds
← Back to all CVEs

CVE-2026-66087

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Oct 08, 2026
Vendor unknown

Description

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the  * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

References