High severity8.8NVD Advisory· Published Aug 25, 2026· Updated Sep 28, 2026
CVE-2026-49050
CVE-2026-49050
Description
General user can mint admin access tokens via /access-tokens
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.4.2
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/17/6nvdMailing ListThird Party Advisory
- lists.apache.org/thread/0lc4t5k6h6nhd8t4hshgjk6yp3cl8sb0nvdMailing ListVendor Advisory
News mentions
1- Apache: 25 Vulnerabilities Across Tomcat, Camel, Hive, and More Disclosed Aug 24-26Vypr Intelligence · Aug 26, 2026