PatchSiren cyber security CVE debrief
CVE-2026-49050 Apache Software Foundation CVE debrief
A general user can mint admin access tokens via /access-tokens in Apache DolphinScheduler before 3.4.2. This vulnerability allows unauthorized access and potential privilege elevation. Users are recommended to upgrade to version 3.4.2. The issue affects Apache DolphinScheduler, specifically versions before 3.4.2, and has a high CVSS score of 8.8, indicating a severe security risk. Administrators and users should assess exposure and prioritize upgrading to version 3.4.2 or later. The vulnerability is exploitable via the /access-tokens endpoint, allowing general users to mint admin access tokens.
- Vendor
- Apache Software Foundation
- Product
- Apache DolphinScheduler
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-09
Who should care
Administrators and users of Apache DolphinScheduler, especially those with general user accounts, should assess exposure and upgrade to version 3.4.2 or later.
Why it matters
CVE-2026-49050 allows general users in Apache DolphinScheduler before version 3.4.2 to mint admin access tokens, potentially leading to unauthorized access and privilege elevation. Administrators should assess exposure, prioritize upgrading to version 3.4.2 or later, and monitor for suspicious activity.
- Potential unauthorized access to sensitive areas of the system
- Possible elevation of privileges for general users
- Need for verification of current system version and exposure
- Priority on upgrading to version 3.4.2 or later
Technical summary
The vulnerability allows a general user to mint admin access tokens via the /access-tokens endpoint in Apache DolphinScheduler before version 3.4.2. This issue has a high CVSS score of 8.8, indicating a severe security risk. The vulnerability is exploitable, allowing general users to gain unauthorized access and potentially elevate privileges. Administrators should assess exposure and prioritize upgrading to version 3.4.2 or later to mitigate the risk.
Defensive priority
Upgrade to version 3.4.2 to fix the issue.
Recommended defensive actions
- Upgrade Apache DolphinScheduler to version 3.4.2 or later
- Review and restrict access to /access-tokens endpoint
- Monitor for suspicious activity related to admin access tokens
Evidence notes
The issue allows a general user to mint admin access tokens via /access-tokens. This affects Apache DolphinScheduler before version 3.4.2. The vulnerability has a high CVSS score of 8.8, indicating a severe security risk. Evidence from the CVE record and NVD detail page confirms the vulnerability and its impact. Defenders should verify affected systems and plan for upgrades or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49050 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49050
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49050 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49050
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/0lc4t5k6h6nhd8t4hshgjk6yp3cl8sb0
[email protected] - Mailing List, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.