SQL Injection Vulnerability in Apache Superset Affects Data Security
CVE-2026-23980
5.3MEDIUM
What is CVE-2026-23980?
A vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands, allowing an authenticated user with read access to perform error-based SQL injection via the sqlExpression or where parameters. This may lead to unauthorized access to sensitive data within the database. Users of affected versions are strongly advised to upgrade to version 6.0.0 to mitigate this risk.
Affected Version(s)
Apache Superset 0.0.0 < 6.0.0