Skip to content
Apache SupersetGHSA-w6c7-j32f-rq8j

Apache Superset Allows Ownership Takeover

Medium8.8CVE-2025-27696 · Published May 13, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 4.1.24.1.2
Details and references

Improper Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 4.1.2 or above, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-285, CWE-863
Also known as
BIT-superset-2025-27696, CVE-2025-27696, PYSEC-2026-1189

More Apache Superset advisories

All Apache Superset

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.