PT-2026-21679 · Apache · Apache Superset

·

CVE-2026-23980

·

Published

2026-02-24

·

Updated

2026-07-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions prior to 6.0.0
Description An issue exists in Apache Superset that allows an authenticated user with read access to conduct error-based SQL injection. This is due to improper neutralization of special elements used in a SQL command. The issue can be triggered via the sqlExpression or where parameters.
Recommendations Upgrade to version 6.0.0 to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SUPERSET-2026-23980
CVE-2026-23980
ECHO-5674-14E4-2B1F
GHSA-GVXG-9HQX-F4RG
PYSEC-2026-2374

Affected Products

Apache Superset