Apache SupersetGHSA-mwf2-qr4v-94h2
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
HighCVE-2026-23984 · Published Feb 24, 2026 · updated Jul 13, 2026
An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data Manipulation Language (DML) statements (e.g., INSERT, UPDATE, DELETE) on read-only connections, it fails to detect them in specially crafted SQL statements. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 6.0.0 | 6.0.0 |
Details and references
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 24 | Apache Superset Improper Authorization allows low-privileged users to bypass access controls | High | 6.0.0 |
| Feb 24 | Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine | Medium | 4.1.2 |
| Feb 24 | Apache Superset allows privileged users to conduct error-based SQL Injection | Medium | 6.0.0 |
| Feb 24 | Apache Superset allows authenticated users to view sensitive data without explicit permissions | Low | 6.0.0 |
| Aug 142025 | Apache Superset data query improperly discloses database schema information to low-privileged guest user | Medium | 4.1.3.post1 |
| Aug 142025 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability | Medium | 5.0.0 |