Sensitive Data Exposure in Apache Superset by Apache
CVE-2026-23983
What is CVE-2026-23983?
A security vulnerability in Apache Superset allows authenticated users to access sensitive user data through the Tag endpoint, which is disabled by default. This endpoint can expose crucial information such as password hashes, email addresses, and login statistics. Even users with low privileges, like those with a Gamma role, can exploit this flaw to view sensitive authentication information, risking the confidentiality of user data. It's essential for users to upgrade to version 6.0.0 or ensure that the TAGGING_SYSTEM setting is set to False, as this is the current default configuration to address the vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Superset 0.0.0 < 6.0.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved