Apache Superset vulnerabilities
68 known vulnerabilities affecting apache/superset.
Total CVEs
68
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
3
Severity breakdown
CRITICAL5HIGH7MEDIUM56
Vulnerabilities
Page 2 of 4
CVE-2026-23983P3MEDIUMCVSS 6.5fixed in 6.0.02026-02-24
CVE-2026-23983 [MEDIUM] CWE-200 CVE-2026-23983: A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to re
A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag.
When these associated objects include Users, the API response improperly serializes and returns sensit
nvd
CVE-2026-23984P3MEDIUMCVSS 6.5fixed in 6.0.02026-02-24
CVE-2026-23984 [MEDIUM] CWE-863 CVE-2026-23984: An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated us
An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection.
While the system effectively blocks standard Data Manipulation Language (DML) statements (e.g., INSERT, UPDATE, DELETE) on read-only connecti
nvd
CVE-2024-55633P3MEDIUMCVSS 6.5fixed in 4.1.02024-12-12
CVE-2024-55633 [MEDIUM] CWE-863 CVE-2024-55633: Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database connections and postgres analytics database connections set with a readonly
nvd
CVE-2025-55674P3MEDIUMCVSS 6.5fixed in 5.0.02025-08-14
CVE-2025-55674 [MEDIUM] CWE-89 CVE-2025-55674: A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the executio
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, leading to the disclosure of sensitive database informatio
nvd
CVE-2023-30776P3MEDIUMCVSS 6.5≥ 1.3.0, ≤ 2.0.12023-04-24
CVE-2023-30776 [MEDIUM] CWE-522 CVE-2023-30776: An authenticated user with specific data permissions could access database connections stored passwo
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.
nvd
CVE-2024-24779P3MEDIUMCVSS 6.5≤ 3.0.4≥ 3.1.0, < 3.1.12024-02-28
CVE-2024-24779 [MEDIUM] CWE-863 CVE-2024-24779: Apache Superset with custom roles that include `can write on dataset` and without all data access pe
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data.
This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.
nvd
CVE-2025-48912P3MEDIUMCVSS 6.5fixed in 4.1.22025-05-30
CVE-2025-48912 [MEDIUM] CWE-89 CVE-2025-48912: An authenticated malicious actor using specially crafted requests could bypass row level security co
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data.
This issue affects Apache Superset: before 4.1.2.
Users are recommended to
nvd
CVE-2025-55675P3MEDIUMCVSS 6.5fixed in 5.0.02025-08-14
CVE-2025-55675 [MEDIUM] CWE-285 CVE-2025-55675: Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missin
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enumerate and confirm the existence and names of protec
nvd
CVE-2023-25504P3MEDIUMCVSS 6.5≤ 2.0.12023-04-17
CVE-2023-25504 [MEDIUM] CWE-918 CVE-2023-25504: A malicious actor who has been authenticated and granted specific permissions in Apache Superset may
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery
attacks and query internal resources on behalf of the server where Superset
is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.
nvd
CVE-2024-24773P3MEDIUMCVSS 6.5fixed in 3.0.4≥ 3.1.0, < 3.1.12024-02-28
CVE-2024-24773 [MEDIUM] CWE-863 CVE-2024-24773: Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their
Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope.
This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.
Users are recommended to upgrade to version 3.1.1, which fixes the issue.
nvd
CVE-2024-23952P3MEDIUMCVSS 6.5fixed in 2.1.3≥ 3.0.0, < 3.0.22024-02-14
CVE-2024-23952 [MEDIUM] CVE-2024-23952: This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset.
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.
This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
nvd
CVE-2023-46104P3MEDIUMCVSS 6.5fixed in 2.1.3≥ 3.0.0, < 3.0.12023-12-19
CVE-2023-46104 [MEDIUM] CWE-400 CVE-2023-46104: Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a maliciou
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.
This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
nvd
CVE-2024-53949P3MEDIUMCVSS 6.5≥ 2.0.0, < 4.1.02024-12-09
CVE-2024-53949 [MEDIUM] CWE-863 CVE-2024-53949: Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabl
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.
issue affects Apache Superset: from 2.0.0 before 4.1.0.
Users are recommended to upgrade to version 4.1.0, which fixes the issue.
nvd
CVE-2021-42250P3MEDIUMCVSS 6.5fixed in 1.3.22021-11-17
CVE-2021-42250 [MEDIUM] CWE-117 CVE-2021-42250: Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an aut
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
nvd
CVE-2023-49734P3MEDIUMCVSS 6.5fixed in 2.1.2≥ 3.0.0, < 3.0.22023-12-19
CVE-2023-49734 [MEDIUM] CWE-863 CVE-2023-49734: An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user wo
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2.
Users are recommended to upgrade to version 3.0.2 o
nvd
CVE-2024-34693P3MEDIUMCVSS 5.3fixed in 3.1.3≥ 4.0.0, < 4.0.12024-06-20
CVE-2024-34693 [MEDIUM] CWE-20 CVE-2024-34693: Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to
Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to execute a specific MySQL/MariaDB SQL com
nvd
CVE-2021-41972P4MEDIUMCVSS 6.5≤ 1.3.12021-11-12
CVE-2021-41972 [MEDIUM] CWE-522 CVE-2021-41972: Apache Superset up to and including 1.3.1 allowed for database connections password leak for authent
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
nvd
CVE-2020-1932P4MEDIUMCVSS 6.5v0.34.0v0.34.1+2 more2020-01-28
CVE-2020-1932 [MEDIUM] CVE-2020-1932: An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Aut
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.
nvd
CVE-2023-42504P4MEDIUMCVSS 6.5fixed in 3.0.02023-11-28
CVE-2023-42504 [MEDIUM] CWE-770 CVE-2023-42504: An authenticated malicious user could initiate multiple concurrent requests, each requesting multipl
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service.
This issue affects Apache Superset: before 3.0.0
nvd
CVE-2022-41703P4MEDIUMCVSS 5.4≤ 1.5.2v2.0.02023-01-16
CVE-2022-41703 [MEDIUM] CWE-89 CVE-2022-41703: A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with re
A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value).
nvd