{"schema_version":1,"title":"apache-superset (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 67 vulnerabilities in apache-superset (PyPI): 0 in the last 7 days and 54 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-23984, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/apache-superset","json_url":"https://junglewise.ai/threats/technologies/apache-superset.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/apache-superset","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":67,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":54,"last_365_days":54},"latest":[{"cve":"CVE-2026-23984","cvss":4,"epss":0.0036,"slug":"cve-2026-23984-apache-superset-read-only-bypass-via-improper-input-validation-on","title":"PYSEC-2026-2376 - Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.178108+00:00","url":"https://junglewise.ai/threats/cve-2026-23984-apache-superset-read-only-bypass-via-improper-input-validation-on"},{"cve":"CVE-2026-23983","cvss":4,"epss":0.0042,"slug":"cve-2026-23983-apache-superset-allows-authenticated-users-to-view-sensitive-data","title":"PYSEC-2026-2375 - Apache Superset allows authenticated users to view sensitive data without explicit permissions","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.123077+00:00","url":"https://junglewise.ai/threats/cve-2026-23983-apache-superset-allows-authenticated-users-to-view-sensitive-data"},{"cve":"CVE-2026-23969","cvss":4,"epss":0.0062,"slug":"cve-2026-23969-apache-superset-incomplete-disallowed-sql-functions-default-list","title":"PYSEC-2026-2373 - Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.073697+00:00","url":"https://junglewise.ai/threats/cve-2026-23969-apache-superset-incomplete-disallowed-sql-functions-default-list"},{"cve":"CVE-2026-23980","cvss":4,"epss":0.0065,"slug":"cve-2026-23980-apache-superset-allows-privileged-users-to-conduct-error-based","title":"PYSEC-2026-2374 - Apache Superset allows privileged users to conduct error-based SQL Injection","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.017444+00:00","url":"https://junglewise.ai/threats/cve-2026-23980-apache-superset-allows-privileged-users-to-conduct-error-based"},{"cve":"CVE-2026-23982","cvss":4,"epss":0.0045,"slug":"cve-2026-23982-apache-superset-improper-authorization-in-dataset-access-controls","title":"PYSEC-2026-2372 - Apache Superset Improper Authorization allows low-privileged users to bypass access controls","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:37.969328+00:00","url":"https://junglewise.ai/threats/cve-2026-23982-apache-superset-improper-authorization-in-dataset-access-controls"},{"cve":"CVE-2021-28125","cvss":3.1,"epss":0.6402,"slug":"cve-2021-28125-open-redirect-in-apache-superset","title":"PYSEC-2026-3078 - Open Redirect in Apache Superset","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:33.778413+00:00","url":"https://junglewise.ai/threats/cve-2021-28125-open-redirect-in-apache-superset"},{"cve":"CVE-2025-55674","cvss":4,"epss":0.007,"slug":"cve-2025-55674-apache-superset-has-bypass-of-disallowed-sql-functions-that","title":"PYSEC-2026-1178 - Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.34968+00:00","url":"https://junglewise.ai/threats/cve-2025-55674-apache-superset-has-bypass-of-disallowed-sql-functions-that"},{"cve":"CVE-2025-55673","cvss":4,"epss":0.0057,"slug":"cve-2025-55673-apache-superset-data-query-improperly-discloses-database-schema","title":"PYSEC-2026-1169 - Apache Superset data query improperly discloses database schema information to low-privileged guest user","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.303749+00:00","url":"https://junglewise.ai/threats/cve-2025-55673-apache-superset-data-query-improperly-discloses-database-schema"},{"cve":"CVE-2025-55672","cvss":4,"epss":0.0074,"slug":"cve-2025-55672-apache-superset-s-chart-visualization-has-a-stored-cross-site","title":"PYSEC-2026-1176 - Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.231+00:00","url":"https://junglewise.ai/threats/cve-2025-55672-apache-superset-s-chart-visualization-has-a-stored-cross-site"},{"cve":"CVE-2025-55675","cvss":4,"epss":0.0053,"slug":"cve-2025-55675-apache-superset-allows-authenticated-users-to-discover-metadata","title":"PYSEC-2026-1186 - Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.155424+00:00","url":"https://junglewise.ai/threats/cve-2025-55675-apache-superset-allows-authenticated-users-to-discover-metadata"},{"cve":"CVE-2025-48912","cvss":4,"epss":0.0072,"slug":"cve-2025-48912-apache-superset-improper-authorization-bypass-on-row-level","title":"PYSEC-2026-1164 - Apache Superset: Improper authorization bypass on row level security via SQL Injection","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:53.582186+00:00","url":"https://junglewise.ai/threats/cve-2025-48912-apache-superset-improper-authorization-bypass-on-row-level"},{"cve":"CVE-2025-27696","cvss":3.1,"epss":0.0121,"slug":"cve-2025-27696-apache-superset-allows-ownership-takeover","title":"PYSEC-2026-1189 - Apache Superset Allows Ownership Takeover","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:52.338043+00:00","url":"https://junglewise.ai/threats/cve-2025-27696-apache-superset-allows-ownership-takeover"},{"cve":"CVE-2024-55633","cvss":3.1,"epss":0.0281,"slug":"cve-2024-55633-apache-superset-sqllab-improper-readonly-query-validation-allows","title":"PYSEC-2026-1162 - Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:47.321105+00:00","url":"https://junglewise.ai/threats/cve-2024-55633-apache-superset-sqllab-improper-readonly-query-validation-allows"},{"cve":"CVE-2024-53948","cvss":3.1,"epss":0.0086,"slug":"cve-2024-53948-apache-superset-error-verbosity-information-disclosure","title":"PYSEC-2026-1154 - Apache Superset: Error verbosity exposes metadata in analytics databases","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:46.975787+00:00","url":"https://junglewise.ai/threats/cve-2024-53948-apache-superset-error-verbosity-information-disclosure"},{"cve":"CVE-2024-53947","cvss":3.1,"epss":0.0084,"slug":"cve-2024-53947-apache-superset-improper-sql-authorisation-parse-not-checking-for","title":"PYSEC-2026-1165 - Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:46.919752+00:00","url":"https://junglewise.ai/threats/cve-2024-53947-apache-superset-improper-sql-authorisation-parse-not-checking-for"},{"cve":"CVE-2024-53949","cvss":3.1,"epss":0.0072,"slug":"cve-2024-53949-apache-superset-authorization-bypass-in-role-creation-api","title":"PYSEC-2026-1156 - Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:46.863785+00:00","url":"https://junglewise.ai/threats/cve-2024-53949-apache-superset-authorization-bypass-in-role-creation-api"},{"cve":"CVE-2024-39887","cvss":3.1,"epss":0.0443,"slug":"cve-2024-39887-apache-superset-improper-sql-authorization-with-engine-functions","title":"PYSEC-2026-1155 - Apache Superset vulnerable to improper SQL authorization","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:36.913009+00:00","url":"https://junglewise.ai/threats/cve-2024-39887-apache-superset-improper-sql-authorization-with-engine-functions"},{"cve":"CVE-2024-34693","cvss":3.1,"epss":0.0158,"slug":"cve-2024-34693-apache-superset-server-arbitrary-file-read","title":"PYSEC-2026-1183 - Apache Superset server arbitrary file read","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:35.071544+00:00","url":"https://junglewise.ai/threats/cve-2024-34693-apache-superset-server-arbitrary-file-read"},{"cve":"CVE-2024-28148","cvss":3.1,"epss":0.0071,"slug":"cve-2024-28148-apache-superset-incorrect-authorization-in-datasource-rest-api","title":"PYSEC-2026-1153 - Apache Superset Incorrect Authorization vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:42.178356+00:00","url":"https://junglewise.ai/threats/cve-2024-28148-apache-superset-incorrect-authorization-in-datasource-rest-api"},{"cve":"CVE-2024-26016","cvss":3.1,"epss":0.0087,"slug":"cve-2024-26016-apache-superset-improper-authorization-validation-on-dashboards","title":"PYSEC-2026-1158 - Apache Superset: Improper authorization validation on dashboards and charts import","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.364923+00:00","url":"https://junglewise.ai/threats/cve-2024-26016-apache-superset-improper-authorization-validation-on-dashboards"},{"cve":"CVE-2024-24779","cvss":3.1,"epss":0.0073,"slug":"cve-2024-24779-apache-superset-improper-data-authorization-when-creating-a-new","title":"PYSEC-2026-1191 - Apache Superset: Improper data authorization when creating a new dataset","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.29499+00:00","url":"https://junglewise.ai/threats/cve-2024-24779-apache-superset-improper-data-authorization-when-creating-a-new"},{"cve":"CVE-2024-24773","cvss":3.1,"epss":0.0078,"slug":"cve-2024-24773-apache-superset-improper-validation-of-sql-statements-allows-for","title":"PYSEC-2026-1160 - Apache Superset: Improper validation of SQL statements allows for unauthorized access to data","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.225746+00:00","url":"https://junglewise.ai/threats/cve-2024-24773-apache-superset-improper-validation-of-sql-statements-allows-for"},{"cve":"CVE-2024-24772","cvss":3.1,"epss":0.0095,"slug":"cve-2024-24772-apache-superset-improper-neutralization-of-custom-sql-on-embedded","title":"PYSEC-2026-1185 - Apache Superset: Improper Neutralization of custom SQL on embedded context","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.156812+00:00","url":"https://junglewise.ai/threats/cve-2024-24772-apache-superset-improper-neutralization-of-custom-sql-on-embedded"},{"cve":"CVE-2024-27315","cvss":3.1,"epss":0.0098,"slug":"cve-2024-27315-apache-superset-improper-error-handling-on-alerts","title":"PYSEC-2026-1181 - Apache Superset: Improper error handling on alerts","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.091102+00:00","url":"https://junglewise.ai/threats/cve-2024-27315-apache-superset-improper-error-handling-on-alerts"},{"cve":"CVE-2023-49734","cvss":3.1,"epss":0.0095,"slug":"cve-2023-49734-apache-superset-incorrect-write-permissions-vulnerability","title":"PYSEC-2026-1180 - Apache Superset incorrect write permissions vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:29.13326+00:00","url":"https://junglewise.ai/threats/cve-2023-49734-apache-superset-incorrect-write-permissions-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":1,"exploited":1,"vulnerabilities":48},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"},{"name":"opencv-contrib-python (PyPI)","slug":"opencv-contrib-python","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/opencv-contrib-python"}],"technology":{"hub":true,"name":"apache-superset (PyPI)","slug":"apache-superset","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/apache-superset"},"most_severe":[{"cve":"CVE-2023-27524","cvss":3.1,"epss":0.9741,"slug":"cve-2023-27524-apache-superset-insecure-default-initialization-of-resource","title":"PYSEC-2026-1161 - Apache superset missing check for default SECRET_KEY","severity":"critical","exploited":true,"published_at":"2026-07-07T11:45:18.61561+00:00","url":"https://junglewise.ai/threats/cve-2023-27524-apache-superset-insecure-default-initialization-of-resource"},{"cve":"CVE-2025-55672","cvss":4,"epss":0.0074,"slug":"cve-2025-55672-apache-superset-s-chart-visualization-has-a-stored-cross-site","title":"PYSEC-2026-1176 - Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.231+00:00","url":"https://junglewise.ai/threats/cve-2025-55672-apache-superset-s-chart-visualization-has-a-stored-cross-site"},{"cve":"CVE-2025-48912","cvss":4,"epss":0.0072,"slug":"cve-2025-48912-apache-superset-improper-authorization-bypass-on-row-level","title":"PYSEC-2026-1164 - Apache Superset: Improper authorization bypass on row level security via SQL Injection","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:53.582186+00:00","url":"https://junglewise.ai/threats/cve-2025-48912-apache-superset-improper-authorization-bypass-on-row-level"},{"cve":"CVE-2025-55674","cvss":4,"epss":0.007,"slug":"cve-2025-55674-apache-superset-has-bypass-of-disallowed-sql-functions-that","title":"PYSEC-2026-1178 - Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.34968+00:00","url":"https://junglewise.ai/threats/cve-2025-55674-apache-superset-has-bypass-of-disallowed-sql-functions-that"},{"cve":"CVE-2026-23980","cvss":4,"epss":0.0065,"slug":"cve-2026-23980-apache-superset-allows-privileged-users-to-conduct-error-based","title":"PYSEC-2026-2374 - Apache Superset allows privileged users to conduct error-based SQL Injection","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.017444+00:00","url":"https://junglewise.ai/threats/cve-2026-23980-apache-superset-allows-privileged-users-to-conduct-error-based"},{"cve":"CVE-2026-23969","cvss":4,"epss":0.0062,"slug":"cve-2026-23969-apache-superset-incomplete-disallowed-sql-functions-default-list","title":"PYSEC-2026-2373 - Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.073697+00:00","url":"https://junglewise.ai/threats/cve-2026-23969-apache-superset-incomplete-disallowed-sql-functions-default-list"},{"cve":"CVE-2025-55673","cvss":4,"epss":0.0057,"slug":"cve-2025-55673-apache-superset-data-query-improperly-discloses-database-schema","title":"PYSEC-2026-1169 - Apache Superset data query improperly discloses database schema information to low-privileged guest user","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.303749+00:00","url":"https://junglewise.ai/threats/cve-2025-55673-apache-superset-data-query-improperly-discloses-database-schema"},{"cve":"CVE-2025-55675","cvss":4,"epss":0.0053,"slug":"cve-2025-55675-apache-superset-allows-authenticated-users-to-discover-metadata","title":"PYSEC-2026-1186 - Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:01.155424+00:00","url":"https://junglewise.ai/threats/cve-2025-55675-apache-superset-allows-authenticated-users-to-discover-metadata"},{"cve":"CVE-2026-23982","cvss":4,"epss":0.0045,"slug":"cve-2026-23982-apache-superset-improper-authorization-in-dataset-access-controls","title":"PYSEC-2026-2372 - Apache Superset Improper Authorization allows low-privileged users to bypass access controls","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:37.969328+00:00","url":"https://junglewise.ai/threats/cve-2026-23982-apache-superset-improper-authorization-in-dataset-access-controls"},{"cve":"CVE-2026-23983","cvss":4,"epss":0.0042,"slug":"cve-2026-23983-apache-superset-allows-authenticated-users-to-view-sensitive-data","title":"PYSEC-2026-2375 - Apache Superset allows authenticated users to view sensitive data without explicit permissions","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.123077+00:00","url":"https://junglewise.ai/threats/cve-2026-23983-apache-superset-allows-authenticated-users-to-view-sensitive-data"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}