Description
General user can mint admin access tokens via /access-tokens



This issue affects Apache DolphinScheduler: before 3.4.2.



Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows any ordinary user to create administrative access tokens by calling the /access-tokens endpoint. Because the issued token grants full control over the DolphinScheduler system, an attacker who can reach this endpoint can gain unrestricted administrative authority over the platform, endangering all stored data, configurations, and scheduled workflows.

Affected Systems

Apache DolphinScheduler versions prior to 3.4.2, deployed by organizations using the default configuration, are susceptible. The weakness is limited to this product and does not affect other Apache components.

Risk and Exploitability

Based on the description, it is inferred that the exploit requires only access to the /access-tokens API, typically available to any authenticated user; unauthenticated access may be possible depending on server configuration. The EPSS score is not available and the vulnerability is not listed in the KEV catalog, yet the potential for a complete administrative takeover provides a high severity assessment. In the absence of a formal CVSS score, the risk remains elevated for any environment running a vulnerable version without mitigation.

Generated by OpenCVE AI on August 25, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache DolphinScheduler to version 3.4.2 or newer.
  • If upgrading is not immediately feasible, reconfigure the system to restrict the /access-tokens endpoint so that only users with administrative roles can invoke it, or block the endpoint with network policies.
  • Continuously monitor application logs for unexpected token creation events and investigate any suspicious activity.

Generated by OpenCVE AI on August 25, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache dolphinscheduler
Vendors & Products Apache
Apache dolphinscheduler

Tue, 25 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
References

Tue, 25 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Title Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens
Weaknesses CWE-863
References

Subscriptions

Apache Dolphinscheduler
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-25T10:12:45.098Z

Reserved: 2026-05-27T09:49:30.794Z

Link: CVE-2026-49050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T10:18:09.430

Modified: 2026-08-25T11:16:53.313

Link: CVE-2026-49050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T12:00:07Z

Weaknesses