{"id":"CVE-2023-27526","aliases":["GHSA-9qc3-p9jq-2x27","BIT-superset-2023-27526","PYSEC-2026-1170"],"title":"Apache Superset users may incorrectly create resources using the import charts feature ","summary":"Apache Superset users may incorrectly create resources using the import charts feature ","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","vendor":"apache-superset","product":"apache-superset","ecosystem":"pip","affected":["apache-superset <= 2.1.0"],"published":"2023-09-06","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9qc3-p9jq-2x27","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27526"},{"url":"https://github.com/apache/superset"},{"url":"https://lists.apache.org/thread/ndww89yl2jd98lvn23n9cj722lfdg8dv"}],"tags":["osv","pip"],"epss":0.01209,"epssPercentile":0.67091,"ingestedAt":"2026-07-08T18:25:48.072Z","slug":"CVE-2023-27526","body":"## Overview\n\nA non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0. \n\n\n## Affected packages\n\n- `apache-superset <= 2.1.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}