CVE-2026-23980

CWE-89SQL Injection5 documents5 sources
Severity
5.3MEDIUM
EPSS
0.0%
top 88.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24

Description

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages3 packages

NVDapache/superset< 6.0.0
PyPIapache-superset< 6.0.0

🔴Vulnerability Details

3
OSV
Apache Superset allows privileged users to conduct error-based SQL Injection2026-02-24
CVEList
Apache Superset: Improper Neutralization of Special Elements used in a SQL Command2026-02-24
GHSA
Apache Superset allows privileged users to conduct error-based SQL Injection2026-02-24

🕵️Threat Intelligence

1
Wiz
CVE-2026-23980 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23980 (MEDIUM CVSS 5.3) | Improper Neutralization of Special | cvebase.io