---
id: CVE-2023-27523
aliases:
  - GHSA-v594-2c97-hx38
  - BIT-superset-2023-27523
  - PYSEC-2026-1187
title: Apache Superset vulnerable to improper data authorization
summary: Apache Superset vulnerable to improper data authorization
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'
vendor: apache-superset
product: apache-superset
ecosystem: pip
affected:
  - apache-superset <= 2.1.0
published: '2023-09-06'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-v594-2c97-hx38'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-27523'
  - url: 'https://github.com/apache/superset'
  - url: 'https://lists.apache.org/thread/3y97nmwm956b6zg3l8dh9oj0w7dj945h'
tags:
  - osv
  - pip
epss: 0.01019
epssPercentile: 0.61853
ingestedAt: '2026-07-08T18:25:53.081Z'
---

## Overview

Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.



## Affected packages

- `apache-superset <= 2.1.0`

## Remediation

Refer to the advisory for the patched release.
