Severity: moderate
Affected versions:
- Apache DolphinScheduler before 3.4.3
Description:
An authorization bypass vulnerability in Apache DolphinScheduler allows
authenticated users to operate task instance in projects they are not
authorized to access through the
*
/dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop
*
/dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Credit:
Meng Qingwei (finder)
h1ei1 (finder)
meifukun (finder)
yansong (finder)
Omar Mousa — Red Team & Security Researcher (finder)
References:
https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-66087