logo

USD 110M Loan Portfolio at Risk Due to Vendor’s Apache Superset Insecure Default Initialization of Resource Vulnerability [CVE-2023-27524]

ID: c6d1b359-ac12-5aa8-a1b7-80034cfb2ddf

STIX ID: report--c6d1b359-ac12-5aa8-a1b7-80034cfb2ddf

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2025-04-10

Date Updated: 2026-04-27

...
...

CloudSEK’s SVigil discovered an unauthenticated Apache Superset dashboard owned by a vendor of a major bank that openly exposed over 2.6 million accounts, USD 110M in outstanding loans, PII, borrower communication logs, and internal co-lending dashboards due to default SECRET_KEY and missing authentication controls; the report details business and regulatory impact and recommends upgrading Superset, enforcing authentication, restricting access, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.