Junglewise Threat Intelligence

CVE-2023-27524: PYSEC-2026-1161 - Apache superset missing check for default SECRET_KEY

CVE-2023-27524 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2026-07-07

Technologies: Apache Superset, apache-superset (PyPI). Vendors: Apache, PyPI.

Executive brief

Apache Superset versions up to 2.0.1 use an insecure default SECRET_KEY for session signing. Attackers can use this known default key to forge session cookies, allowing them to authenticate and access unauthorized resources on installations that have not changed the default configuration.

Affected products

  • Apache Superset up to and including 2.0.1

Timeline

  • 2023-04-24: disclosed: Initial disclosure on oss-security mailing list
  • 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-08: other: Published to NVD

Related threats