Get real-time updates on Telegram
P5Verified
CVE-2026-66087: Apache DolphinScheduler 0 to before 3.4.3
CVE-2026-66087. EPSS 0.00164 (percentile 0.05076), scored 2026-10-08.
Affected technology
Apache DolphinScheduler · 0 to before 3.4.3
Apache Software Foundation
Component: Not specified by the source
What an attacker can do
Authenticated users can operate task instance in projects they are not authorized to access through the * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinScheduler: before 3.4.3.
- CWE
- CWE-863
- CCR priority
- 0.0 /100 (P5)
- EPSS
- 0.00164 · percentile 0.05076 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-08 18:27:24.781324+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-66087.html