SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-49050

HIGH · CVSS 8.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Apache DolphinScheduler versions prior to 3.4.2 are vulnerable to a security flaw that allows general users to mint admin access tokens through the /access-tokens endpoint. This could lead to unauthorized administrative access, potentially compromising the integrity and security of the application. Organizations using affected versions should prioritize upgrading to 3.4.2 to mitigate this risk.

CVE
CVE-2026-49050
Severity
HIGH
CVSS
8.8
EPSS
0.34%
Apache

Original NVD Description

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)