Skip to content
Apache SupersetGHSA-9qc3-p9jq-2x27

Apache Superset users may incorrectly create resources using the import charts feature

Medium4.3CVE-2023-27526 · Published Sep 6, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.1.0No fix yet
Details and references

A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0. 

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2023-27526, CVE-2023-27526, PYSEC-2026-1170

More Apache Superset advisories

All Apache Superset
DateAdvisory
Sep 62023Apache Superset Server Side Request Forgery vulnerability
CVE-2023-36388Medium4.3no fix yet
Sep 62023Apache Superset has improper default REST API permission for Gamma users
CVE-2023-36387Medium5.4no fix yet
Sep 62023Apache Superset may expose internal traces on REST API endpoints
CVE-2023-39264Medium4.3no fix yet
Sep 62023Apache Superset vulnerable to improper data authorization
CVE-2023-27523Medium5.0no fix yet
Sep 62023Apache Superset has incorrect authorization check
CVE-2023-32672Medium4.3no fix yet
Sep 62023Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-37941Medium6.6fixed in 2.1.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.