Apache · Dolphinscheduler · CVE-2026-49050
**Name of the Vulnerable Software and Affected Versions**
Apache DolphinScheduler versions prior to 3.4.2
**Description**
A general user can mint admin access tokens through the '/access-tokens' endpoint.
**Recommendations**
Upgrade to version 3.4.2.