CVE-2023-39265Medium· 6.5▾ TwilightPoC availableApache Superset Improper Input Validation vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 17.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
84%
84% → 86%
Metasploit ×1
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Additionally, if Apache Superset is using a SQLite database for its metadata (not advised for production use) it could result in more severe vulnerabilities related to confidentiality and integrity. This vulnerability exists in Apache Superset versions up to and including 2.1.0.
apache-superset <= 2.1.0Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-37941Medium· 6.6Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2026-23980MediumApache Superset allows privileged users to conduct error-based SQL Injection
CVE-2024-34693Medium· 6.8Apache Superset server arbitrary file read
CVE-2023-27524High· 8.9Apache superset missing check for default SECRET_KEY
CVE-2024-39887Medium· 4.3Apache Superset vulnerable to improper SQL authorization
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections