Improper Authorization in Apache Superset Affects Dashboard Security
CVE-2026-23981
5.3MEDIUM
What is CVE-2026-23981?
An improper authorization vulnerability exists in Apache Superset, allowing authenticated users with chart update permissions to modify dashboards they do not own. When utilizing the REST API to update chart properties, users can associate charts with multiple dashboard IDs without adequate validation of their permissions for those dashboards. The lack of proper checks in the UpdateChartCommand exposes sensitive dashboard modifications to unauthorized users, potentially compromising the integrity of dashboard management. It is essential for affected users to upgrade to version 6.0.0 to mitigate this vulnerability.
Affected Version(s)
Apache Superset 0.0.0 < 6.0.0