← Vulnerability feed

Vulnerability record · CVE-2023-27524 · published 24 April 2023

CVE-2023-27524: Apache Superset default SECRET_KEY allows session forgery and auth bypass

Apache · Superset

Apache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cookies and authenticate as any user. Because the key also encrypts sensitive database content, exposure extends beyond simple login bypass. Only installations that changed the default value are unaffected.

9.8 CVSS 3.1 Critical CISA KEV since 8 Jan 2024 EPSS 97% · top 0.1% CWE-1188 · Insecure default initialization
9.8CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing and near-maximum EPSS with public exploit code make this an urgent, actively targeted flaw.

What it is

Apache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cookies and authenticate as any user. Because the key also encrypts sensitive database content, exposure extends beyond simple login bypass. Only installations that changed the default value are unaffected.

Impact

An unauthenticated attacker gains authenticated access to Superset and any resources reachable with the forged identity, and can potentially decrypt sensitive data protected by the same key. Reference material also links this flaw to remote code execution chains.

Attack surface

Reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The attacker only needs to know or guess the default SECRET_KEY to craft a valid session cookie.

Exploitation

Listed in CISA KEV with a due date of 2024-01-29, and EPSS shows a 30-day probability of roughly 0.97 at the 99.9th percentile. Public exploit references exist, including an authentication bypass and an RCE writeup.

What to do

  • Upgrade Apache Superset past 2.0.1 to a release that does not ship a default SECRET_KEY.
  • Set a unique, strong random SECRET_KEY in superset_config.py or via the SUPERSET_SECRET_KEY environment variable.
  • Rotate the SECRET_KEY on any instance that may have run with the default, invalidating existing sessions.
  • Audit Superset instances for unauthorized accounts, sessions or configuration changes made before remediation.

Detection

  • Search Superset configuration and environment for the known default SECRET_KEY value.
  • Review authentication logs for sessions or logins that do not correspond to legitimate user activity.
  • Monitor for anomalous access to Superset admin endpoints or database connections following session creation.
  • Alert on Superset instances running versions 2.0.1 or earlier that have not confirmed a custom SECRET_KEY.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-27524 to the Known Exploited Vulnerabilities catalog on 8 January 2024 as "Apache Superset Insecure Default Initialization of Resource Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 29 January 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27524 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-39887Apache superset sql injection vulnerabilityAn SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…EPSS 4.4%9.8CVE-2022-27479Apache superset sql injection vulnerabilityApache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.EPSS 2.9%9.8CVE-2018-8021Apache Superset pickle deserialization remote code executionApache Superset versions prior to 0.23 deserialized data with an unsafe pickle load method, allowing untrusted serialized data to be executed as code…EPSS 53%analysed8.8CVE-2023-49736Apache superset sql injection vulnerabilityA where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup…EPSS 1.2%8.8CVE-2023-40610Apache superset incorrect authorization vulnerabilityImproper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…EPSS 1.3%8.8CVE-2022-43719Apache superset cross-site request forgery vulnerabilityTwo legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…EPSS 0.57%8.8CVE-2021-41971Apache superset sql injection vulnerabilityApache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic…EPSS 1.8%8.8CVE-2020-13948Apache superset vulnerabilityWhile investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2023-27524), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.