Impact
The vulnerability allows any ordinary user to create administrative access tokens by calling the /access-tokens endpoint. Because the issued token grants full control over the DolphinScheduler system, an attacker who can reach this endpoint can gain unrestricted administrative authority over the platform, endangering all stored data, configurations, and scheduled workflows.
Affected Systems
Apache DolphinScheduler versions prior to 3.4.2, deployed by organizations using the default configuration, are susceptible. The weakness is limited to this product and does not affect other Apache components.
Risk and Exploitability
Based on the description, it is inferred that the exploit requires only access to the /access-tokens API, typically available to any authenticated user; unauthenticated access may be possible depending on server configuration. The EPSS score is not available and the vulnerability is not listed in the KEV catalog, yet the potential for a complete administrative takeover provides a high severity assessment. In the absence of a formal CVSS score, the risk remains elevated for any environment running a vulnerable version without mitigation.
OpenCVE Enrichment