CVE-2026-23982 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Sup…
High CVSS: 7.1

CVE-2026-23982

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authenticated attacker with permissions to write datasets and read charts can bypass these checks by overwriting the SQL query of an existing dataset.

This issue affects Apache Superset: before 6.0.0.

Users are recommended to upgrade to version 6.0.0, which fixes the issue.
Vendor
Apache
Product
Superset
CWE
CWE-863
Yayın Tarihi
2026-02-24 14:16:22
Güncelleme
2026-02-25 14:38:02
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar