Improper Authorization in Apache Superset Affects Dashboard Security
CVE-2026-23981

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 July 2026

What is CVE-2026-23981?

An improper authorization vulnerability exists in Apache Superset, allowing authenticated users with chart update permissions to modify dashboards they do not own. When utilizing the REST API to update chart properties, users can associate charts with multiple dashboard IDs without adequate validation of their permissions for those dashboards. The lack of proper checks in the UpdateChartCommand exposes sensitive dashboard modifications to unauthorized users, potentially compromising the integrity of dashboard management. It is essential for affected users to upgrade to version 6.0.0 to mitigate this vulnerability.

Affected Version(s)

Apache Superset 0.0.0 < 6.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Đỗ Thành Đạt
Daniel Gaspar
.