PT-2026-21681 · Apache · Apache Superset

·

CVE-2026-23983

·

Published

2026-02-24

·

Updated

2026-07-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions prior to 6.0.0
Description A sensitive data exposure issue exists in Apache Superset that allows authenticated users to retrieve sensitive user information. The '/api/v1/tag' API endpoint, when enabled, improperly serializes and returns sensitive fields associated with user objects, including password hashes (pbkdf2), email addresses, and login statistics. Users with low privileges, such as those with the Gamma role, can view this sensitive authentication data.
Recommendations Upgrade to version 6.0.0, which resolves the issue. Ensure TAGGING SYSTEM is set to False, as this is the default configuration for Apache Superset.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SUPERSET-2026-23983
CVE-2026-23983
ECHO-91E6-90E7-361A
GHSA-H294-8FXM-M2PJ
PYSEC-2026-2375

Affected Products

Apache Superset