CVE-2026-49050

Summary

General user can mint admin access tokens via /access-tokens

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache DolphinScheduler0 < 3.4.2affected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References