Sensitive Data Exposure in Apache Superset by Apache
CVE-2026-23983

2.3LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 February 2026

What is CVE-2026-23983?

A security vulnerability in Apache Superset allows authenticated users to access sensitive user data through the Tag endpoint, which is disabled by default. This endpoint can expose crucial information such as password hashes, email addresses, and login statistics. Even users with low privileges, like those with a Gamma role, can exploit this flaw to view sensitive authentication information, risking the confidentiality of user data. It's essential for users to upgrade to version 6.0.0 or ensure that the TAGGING_SYSTEM setting is set to False, as this is the current default configuration to address the vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Apache Superset 0.0.0 < 6.0.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Maurek
Daniel Gaspar
.