GHSA-3m2g-v7jf-7fxc

Suggest an improvement
Source
https://github.com/advisories/GHSA-3m2g-v7jf-7fxc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-3m2g-v7jf-7fxc/GHSA-3m2g-v7jf-7fxc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3m2g-v7jf-7fxc
Aliases
Published
2026-02-24T15:30:30Z
Modified
2026-02-26T15:41:11.403167Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
Details

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authenticated attacker with permissions to write datasets and read charts can bypass these checks by overwriting the SQL query of an existing dataset.

This issue affects Apache Superset: before 6.0.0.

Users are recommended to upgrade to version 6.0.0, which fixes the issue.

Database specific
{
    "nvd_published_at": "2026-02-24T14:16:22Z",
    "severity": "HIGH",
    "github_reviewed_at": "2026-02-26T15:28:38Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "github_reviewed": true
}
References

Affected packages

PyPI / apache-superset

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.0

Affected versions

0.*
0.34.0
0.34.1
0.35.1
0.35.2
0.36.0
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
1.*
1.0.0
1.0.1
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
2.*
2.0.0
2.0.1
2.1.0
2.1.1rc1
2.1.1rc2
2.1.1rc3
2.1.1
2.1.2
2.1.3
3.*
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0rc1
3.1.0rc2
3.1.0rc3
3.1.0rc4
3.1.0
3.1.1
3.1.2
3.1.3
4.*
4.0.0rc1
4.0.0rc2
4.0.0
4.0.1
4.0.2
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0
4.1.1rc1
4.1.1
4.1.2rc1
4.1.2
4.1.3rc1
4.1.3rc2
4.1.3.post1
4.1.4rc1
4.1.4
5.*
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.0.0rc4
5.0.0
6.*
6.0.0rc1
6.0.0rc2
6.0.0rc3
6.0.0rc4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-3m2g-v7jf-7fxc/GHSA-3m2g-v7jf-7fxc.json"