Skip to content
Apache SupersetGHSA-35fc-9hrj-3585

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

High6.5CVE-2024-53949 · Published Dec 9, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
>= 2.0.0, < 4.1.04.1.0
Details and references

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-285, CWE-863
Also known as
BIT-superset-2024-53949, CVE-2024-53949, PYSEC-2026-1156

More Apache Superset advisories

All Apache Superset
DateAdvisory
Dec 92024Apache Superset: Error verbosity exposes metadata in analytics databases
CVE-2024-53948Medium5.3fixed in 4.1.0
Dec 92024Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
CVE-2024-53947Low9.8fixed in 4.1.0
Dec 122024Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
CVE-2024-55633High6.5fixed in 4.1.0
Jul 162024Apache Superset vulnerable to improper SQL authorization
CVE-2024-39887Medium4.3fixed in 4.0.2
May 132025Apache Superset Allows Ownership Takeover
CVE-2025-27696Medium8.8fixed in 4.1.2
Jun 202024Apache Superset server arbitrary file read
CVE-2024-34693Medium6.8fixed in 3.1.3, 4.0.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.