PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49050 Apache Software Foundation CVE debrief

A general user can mint admin access tokens via /access-tokens in Apache DolphinScheduler before 3.4.2. This vulnerability allows unauthorized access and potential privilege elevation. Users are recommended to upgrade to version 3.4.2. The issue affects Apache DolphinScheduler, specifically versions before 3.4.2, and has a high CVSS score of 8.8, indicating a severe security risk. Administrators and users should assess exposure and prioritize upgrading to version 3.4.2 or later. The vulnerability is exploitable via the /access-tokens endpoint, allowing general users to mint admin access tokens.

Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-09
Advisory published
2026-08-25
Advisory updated
2026-09-09

Who should care

Administrators and users of Apache DolphinScheduler, especially those with general user accounts, should assess exposure and upgrade to version 3.4.2 or later.

Why it matters

CVE-2026-49050 allows general users in Apache DolphinScheduler before version 3.4.2 to mint admin access tokens, potentially leading to unauthorized access and privilege elevation. Administrators should assess exposure, prioritize upgrading to version 3.4.2 or later, and monitor for suspicious activity.

  • Potential unauthorized access to sensitive areas of the system
  • Possible elevation of privileges for general users
  • Need for verification of current system version and exposure
  • Priority on upgrading to version 3.4.2 or later

Technical summary

The vulnerability allows a general user to mint admin access tokens via the /access-tokens endpoint in Apache DolphinScheduler before version 3.4.2. This issue has a high CVSS score of 8.8, indicating a severe security risk. The vulnerability is exploitable, allowing general users to gain unauthorized access and potentially elevate privileges. Administrators should assess exposure and prioritize upgrading to version 3.4.2 or later to mitigate the risk.

Defensive priority

Upgrade to version 3.4.2 to fix the issue.

Recommended defensive actions

  • Upgrade Apache DolphinScheduler to version 3.4.2 or later
  • Review and restrict access to /access-tokens endpoint
  • Monitor for suspicious activity related to admin access tokens

Evidence notes

The issue allows a general user to mint admin access tokens via /access-tokens. This affects Apache DolphinScheduler before version 3.4.2. The vulnerability has a high CVSS score of 8.8, indicating a severe security risk. Evidence from the CVE record and NVD detail page confirms the vulnerability and its impact. Defenders should verify affected systems and plan for upgrades or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49050 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49050

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49050 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49050

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.