This issue affects Apache Superset: before 6.0.0.
Users are recommended to upgrade to version 6.0.0, which fixes the issue.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 24 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authenticated attacker with permissions to write datasets and read charts can bypass these checks by overwriting the SQL query of an existing dataset. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue. | |
| Title | Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-02-24T15:45:13.456Z
Reserved: 2026-01-19T16:52:17.333Z
Link: CVE-2026-23982
Updated: 2026-02-24T15:45:06.156Z
Status : Received
Published: 2026-02-24T14:16:22.980
Modified: 2026-02-24T14:16:22.980
Link: CVE-2026-23982
No data.
OpenCVE Enrichment
No data.