Skip to main content

Vendor/product archive

apache / superset CVEs

Beta · best-effort

68 CVEs tagged to apache / superset3 Critical, 11 High, 50 Medium, 4 Low, 0 Unrated.

CVE-2026-23984

Published Feb 24, 2026

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a P…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-23983

Published Feb 24, 2026

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allow…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-23982

Published Feb 24, 2026

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces perm…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-23980

Published Feb 24, 2026

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-23969

Published Feb 24, 2026

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While thi…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-55675

Published Aug 14, 2025

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55674

Published Aug 14, 2025

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55673

Published Aug 14, 2025

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying que…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55672

Published Aug 14, 2025

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious pay…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48912

Published May 30, 2025

An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the exec…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27696

Published May 13, 2025

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55633

Published Dec 12, 2024

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Inc…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53949

Published Dec 9, 2024

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affec…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53948

Published Dec 9, 2024

Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53947

Published Dec 9, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not chec…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-39887

Published Jul 16, 2024

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34693

Published Jun 20, 2024

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB serv…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28148

Published May 7, 2024

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Supers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26016

Published Feb 28, 2024

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the objec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24779

Published Feb 28, 2024

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24773

Published Feb 28, 2024

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, fr…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24772

Published Feb 28, 2024

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects A…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27315

Published Feb 28, 2024

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23952

Published Feb 14, 2024

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacke…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49657

Published Jan 23, 2024

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could st…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 68 CVEsPage 1 of 3