First published: Mon May 12 2025(Updated: )
Improper Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 4.1.2 or above, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | <=4.1.1 | |
pip/apache-superset | <4.1.2 | 4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27696 has a moderate severity level due to its potential for authorized users to gain ownership of sensitive dashboards and datasets.
To fix CVE-2025-27696, upgrade Apache Superset to version 4.1.2 or above.
CVE-2025-27696 affects all authenticated users with read permissions in Apache Superset versions up to 4.1.1.
CVE-2025-27696 is categorized as an Improper Authorization vulnerability.
CVE-2025-27696 can lead to unauthorized takeover of dashboards, charts, and datasets.