CVE-2026-49050: Apache Dolphinscheduler

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Affected products

  • Apache Dolphinscheduler: before 3.4.2 (fixed in 3.4.2)

Published 2026-08-25. Last modified 2026-09-28.