Junglewise Threat Intelligence

CVE-2024-39887: PYSEC-2026-1155 - Apache Superset vulnerable to improper SQL authorization

CVE-2024-39887 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: Apache Superset, apache-superset (PyPI). Vendors: Apache, PyPI.

Executive brief

Apache Superset is a data visualization and business intelligence platform that allows users to query databases through a web interface. An authorization bypass flaw permits authenticated users to execute unauthorized SQL commands using certain database-specific functions (such as PostgreSQL's version(), query_to_xml(), inet_server_addr(), and inet_client_addr()) that were not properly restricted. An attacker with legitimate database access could exploit this to extract sensitive information or manipulate data beyond their intended permissions.

Technical details

This vulnerability is an SQL injection/authorization bypass (CWE-89) caused by improper neutralization of special SQL elements. The root cause is insufficient validation of certain database engine-specific functions in SQL queries. An authenticated attacker with SQL execution privileges can bypass Superset's SQL authorization controls by using functions like PostgreSQL's version(), query_to_xml(), inet_server_addr(), and inet_client_addr() to extract unauthorized information. The vulnerability requires prior authentication and network access to the Superset instance. A mitigation was implemented via a new DISALLOWED_SQL_FUNCTIONS configuration key that allows administrators to blacklist dangerous functions per database engine. The fix is available in Superset 4.0.2 and later.

Affected products

  • Apache Superset before 4.0.2

Timeline

  • 2024-07-16: disclosed
  • 2024-07-16: patched: fix available in version 4.0.2

References

Related threats