Apache SupersetGHSA-48m2-v2r8-h23m
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
MediumCVE-2026-23969 · Published Feb 24, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 4.1.2 | 4.1.2 |
Details and references
Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was reported where the default list for the ClickHouse engine was incomplete. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-89
- Also known as
- BIT-superset-2026-23969, CVE-2026-23969, PYSEC-2026-2373
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 24 | Apache Superset Improper Authorization allows low-privileged users to bypass access controls CVE-2026-23982Highfixed in 6.0.0 | High | 6.0.0 |
| Feb 24 | Apache Superset allows privileged users to conduct error-based SQL Injection CVE-2026-23980Mediumfixed in 6.0.0 | Medium | 6.0.0 |
| Feb 24 | Apache Superset allows authenticated users to view sensitive data without explicit permissions CVE-2026-23983Lowfixed in 6.0.0 | Low | 6.0.0 |
| Feb 24 | Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections CVE-2026-23984Highfixed in 6.0.0 | High | 6.0.0 |
| Aug 142025 | Apache Superset data query improperly discloses database schema information to low-privileged guest user CVE-2025-55673Mediumfixed in 4.1.3.post1 | Medium | 4.1.3.post1 |
| Aug 142025 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability CVE-2025-55672Mediumfixed in 5.0.0 | Medium | 5.0.0 |