CVE-2026-49050: Apache Dolphinscheduler
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Affected products
- Apache Dolphinscheduler: before 3.4.2 (fixed in 3.4.2)
Published 2026-08-25. Last modified 2026-09-28.