
Apache Superset authorization bypass via dataset SQL overwrite
Apache disclosed CVE-2026-23982, a High-severity authorization bypass in Superset versions before 6.0.0 enabling low-privilege users to access restricted data via dataset SQL overwrite.
NewsVulnerabilitiesWeb Security
1 min24 Feb 2026
