Skip to content
Apache SupersetGHSA-3v9r-885j-762g

Apache Superset: Improper authorization validation on dashboards and charts import

Medium4.3CVE-2024-26016 · Published Feb 28, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.0.43.0.4
>= 3.1.0, < 3.1.13.1.1
Details and references

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these charts and dashboards would still be subject to validation based on data access privileges. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.Users are recommended to upgrade to version 3.1.1, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2024-26016, CVE-2024-26016, PYSEC-2026-1158

More Apache Superset advisories

All Apache Superset
DateAdvisory
Feb 282024Apache Superset: Improper error handling on alerts
CVE-2024-27315Medium4.3fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
CVE-2024-24773Medium4.9fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper Neutralization of custom SQL on embedded context
CVE-2024-24772Medium4.3fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper data authorization when creating a new dataset
CVE-2024-24779Medium5.0fixed in 3.0.4, 3.1.1
Jan 232024Cross-site Scripting in Apache superset
CVE-2023-49657Critical9.6fixed in 3.0.3
May 72024Apache Superset Incorrect Authorization vulnerability
CVE-2024-28148Medium4.3fixed in 3.1.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.