CVE-2026-23983Low▾ SunlitApache Superset allows authenticated users to view sensitive data without explicit permissions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects include Users, the API response improperly serializes and returns sensitive fields, including password hashes (pbkdf2), email addresses, and login statistics. This vulnerability allows authenticated users with low privileges (e.g., Gamma role) to view sensitive authentication data
This issue affects Apache Superset: before 6.0.0.
Users are recommended to upgrade to version 6.0.0, which fixes the issue or make sure TAGGING_SYSTEM is False (Apache Superset current default)
apache-superset < 6.0.0Upgrade to a patched release:
apache-superset 6.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23980MediumApache Superset allows privileged users to conduct error-based SQL Injection
CVE-2026-23969MediumApache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
CVE-2026-23982HighApache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2024-24779Medium· 5.0Apache Superset: Improper data authorization when creating a new dataset
CVE-2023-43701Medium· 4.3Apache Superset Cross-site Scripting vulnerability