{"id":"CVE-2026-23980","aliases":["GHSA-gvxg-9hqx-f4rg","BIT-superset-2026-23980","PYSEC-2026-2374"],"title":"Apache Superset allows privileged users to conduct error-based SQL Injection","summary":"Apache Superset allows privileged users to conduct error-based SQL Injection","severity":"medium","vendor":"apache-superset","product":"apache-superset","ecosystem":"pip","affected":["apache-superset < 6.0.0"],"patched":["apache-superset 6.0.0"],"published":"2026-02-24","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-gvxg-9hqx-f4rg","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23980"},{"url":"https://github.com/apache/superset"},{"url":"https://lists.apache.org/thread/h4l02zw1pr2vywv0dc5zjn3grdcdhwf4"},{"url":"http://www.openwall.com/lists/oss-security/2026/02/24/5"}],"tags":["osv","pip","exploit-available"],"epss":0.00615,"epssPercentile":0.4778,"ingestedAt":"2026-07-13T18:57:58.616Z","exploits":{"github":2,"githubRepos":["https://github.com/oscar-mine/CVE-2026-23980-Exploit","https://github.com/hyphenTBG/CVE-2026-23980"],"checkedAt":"2026-09-21T15:28:31.138Z"},"exploitAvailable":true,"slug":"CVE-2026-23980","body":"## Overview\n\nImproper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters.\n\nThis issue affects Apache Superset: before 6.0.0.\n\nUsers are recommended to upgrade to version 6.0.0, which fixes the issue.\n\n## Affected packages\n\n- `apache-superset < 6.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `apache-superset 6.0.0`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5025,"id":"CVE-2026-23980","ts":1788887229166,"field":"exploit_available","old":"false","new":"true"},{"seq":3908,"id":"CVE-2026-23980","ts":1788886360219,"field":"exploit_available","old":"true","new":"false"},{"seq":2730,"id":"CVE-2026-23980","ts":1788883026014,"field":"exploit_available","old":"false","new":"true"},{"seq":1759,"id":"CVE-2026-23980","ts":1788882430009,"field":"exploit_available","old":"true","new":"false"},{"seq":865,"id":"CVE-2026-23980","ts":1788881863000,"field":"exploit_available","old":"false","new":"true"}]}