← Vulnerability feed

Vulnerability record · CVE-2026-23983 · published 24 February 2026

CVE-2026-23983: Apache superset information exposure vulnerability

Apache · Superset

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects include Users, the API response improperly serializes and returns sensitive fields, including password hashes (pbkdf2), email addresses, and login statistics. This vulnerability allows authenticated users with low privileges (e.g., Gamma role) to view sensitive authentication data This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue or make sure TAGGING_SYSTEM is False (Apache Superset current default)

2.3 CVSS 4.0 Low EPSS 0.42% · top 66.6% CWE-200 · Information exposure
2.3CVSS 4.0 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects include Users, the API response improperly serializes and returns sensitive fields, including password hashes (pbkdf2), email addresses, and login statistics. This vulnerability allows authenticated users with low privileges (e.g., Gamma role) to view sensitive authentication data This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue or make sure TAGGING_SYSTEM is False (Apache Superset current default)

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23983 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27524Apache Superset default SECRET_KEY allows session forgery and auth bypassApache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cook…KEVEPSS 97%analysed9.8CVE-2024-39887Apache superset sql injection vulnerabilityAn SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…EPSS 4.4%9.8CVE-2022-27479Apache superset sql injection vulnerabilityApache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.EPSS 2.9%9.8CVE-2018-8021Apache Superset pickle deserialization remote code executionApache Superset versions prior to 0.23 deserialized data with an unsafe pickle load method, allowing untrusted serialized data to be executed as code…EPSS 53%analysed8.8CVE-2023-49736Apache superset sql injection vulnerabilityA where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup…EPSS 1.2%8.8CVE-2023-40610Apache superset incorrect authorization vulnerabilityImproper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…EPSS 1.3%8.8CVE-2022-43719Apache superset cross-site request forgery vulnerabilityTwo legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…EPSS 0.57%8.8CVE-2021-41971Apache superset sql injection vulnerabilityApache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2026-23983), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.