CVE-2026-49050: Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens
General user can mint admin access tokens via /access-tokens
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache DolphinSchedulerto a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49050?
CVE-2026-49050 is rated as a critical vulnerability due to its potential to grant unauthorized admin access.
How do I fix CVE-2026-49050?
To fix CVE-2026-49050, you should upgrade to the latest version of Apache DolphinScheduler where the vulnerability has been patched.
What systems are affected by CVE-2026-49050?
CVE-2026-49050 affects all versions of Apache DolphinScheduler prior to the security patch release.
What are the risks associated with CVE-2026-49050?
The risks of CVE-2026-49050 include unauthorized access to admin functionalities, which could lead to data breaches or system compromise.
Is there a workaround for CVE-2026-49050 before patching?
A temporary workaround for CVE-2026-49050 is to restrict access to the /access-tokens endpoint until a patch is applied.