SQL Function Restrictions in Apache Superset Uncovered
CVE-2026-23969
5.3MEDIUM
What is CVE-2026-23969?
A security issue in Apache Superset pertains to the DISALLOWED_SQL_FUNCTIONS dictionary, intended to limit the execution of sensitive SQL functions. The vulnerability is specifically related to an incomplete restrictions list for the ClickHouse database engine, potentially allowing unauthorized SQL functions to be executed. It is crucial for users to upgrade to version 4.1.2 or later to ensure comprehensive protection against this issue.
Affected Version(s)
Apache Superset 0.0.0 < 4.1.2