CVE-2023-27524High· 8.9▾ Abyssal⚠ Exploited in the wildPoC availableApache superset missing check for default SECRET_KEY
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 49 · likelihood 19.5 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 4 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Federal remediation due Jan 29, 2024
Last analysed / modified upstream
97%
Exploit-DB · 14 GitHub repos · Metasploit ×2 · Nuclei ×1 (last check)
Added to the CISA catalog on Jan 8, 2024. Federal remediation due Jan 29, 2024. View catalog ↗
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.
apache-superset < 2.1.0Upgrade to a patched release:
apache-superset 2.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23980MediumApache Superset allows privileged users to conduct error-based SQL Injection
CVE-2024-34693Medium· 6.8Apache Superset server arbitrary file read
CVE-2023-39265Medium· 6.5Apache Superset Improper Input Validation vulnerability
CVE-2023-37941Medium· 6.6Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2024-39887Medium· 4.3Apache Superset vulnerable to improper SQL authorization
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections