CVE-2026-23980: Apache Superset: Improper Neutralization of Special Elements used in a SQL Command
Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters.
This issue affects Apache Superset: before 6.0.0.
Users are recommended to upgrade to version 6.0.0, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23980?
CVE-2026-23980 has a high severity rating due to its potential for SQL injection attacks.
How do I fix CVE-2026-23980?
To fix CVE-2026-23980, upgrade Apache Superset to version 6.0.0 or later.
Who is affected by CVE-2026-23980?
CVE-2026-23980 affects authenticated users of Apache Superset versions prior to 6.0.0.
What type of vulnerability is CVE-2026-23980?
CVE-2026-23980 is classified as an SQL Injection vulnerability.
Can CVE-2026-23980 be exploited remotely?
CVE-2026-23980 requires authentication, thus it can only be exploited by authenticated users.