Sensitive Data Exposure in Apache Superset by Apache
CVE-2026-23983
2.3LOW
What is CVE-2026-23983?
A security vulnerability in Apache Superset allows authenticated users to access sensitive user data through the Tag endpoint, which is disabled by default. This endpoint can expose crucial information such as password hashes, email addresses, and login statistics. Even users with low privileges, like those with a Gamma role, can exploit this flaw to view sensitive authentication information, risking the confidentiality of user data. It's essential for users to upgrade to version 6.0.0 or ensure that the TAGGING_SYSTEM setting is set to False, as this is the current default configuration to address the vulnerability.
Affected Version(s)
Apache Superset 0.0.0 < 6.0.0