logo

Major Security Overhaul for Apache Superset: Five Vulnerabilities Patched

ID: 4ff3bb46-ed73-5cd3-b928-5a3b9a266765

STIX ID: report--4ff3bb46-ed73-5cd3-b928-5a3b9a266765

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-26

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache Superset security advisory: five vulnerabilities were disclosed affecting Superset releases before 6.0.0 (and before 4.1.2 for one ClickHouse issue). Two high-severity flaws enable a PostgreSQL SQLLab read-only bypass (CVE-2026-23984) and an authorization bypass when creating datasets (CVE-2026-23982); two medium issues include an authenticated SQL injection via sqlExpression/where (CVE-2026-23980) and incomplete ClickHouse function filtering (CVE-2026-23969); a low-severity issue exposes sensitive user data via the Tag API (CVE-2026-23983). Administrators are advised to upgrade (to 6.0.0 or 4.1.2 as applicable) or apply recommended configuration changes (e.g., disable TAGGING_SYSTEM) to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.