Skip to content
Apache SupersetGHSA-h294-8fxm-m2pj

Apache Superset allows authenticated users to view sensitive data without explicit permissions

LowCVE-2026-23983 · Published Feb 24, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 6.0.06.0.0
Details and references

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects include Users, the API response improperly serializes and returns sensitive fields, including password hashes (pbkdf2), email addresses, and login statistics. This vulnerability allows authenticated users with low privileges (e.g., Gamma role) to view sensitive authentication data This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue or make sure TAGGING_SYSTEM is False (Apache Superset current default)

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-superset-2026-23983, CVE-2026-23983, PYSEC-2026-2375

More Apache Superset advisories

All Apache Superset

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.