https://seclists.org/oss-sec/2025/q2/119: CVE-2025-27696: Apache Superset: Improper authorization leading to source ownership takeover
Published May 12, 2025
·Updated
Affected Software
1 affected component
Apache Superset<=4.1.1
Frequently Asked Questions
1
What is the severity of CVE-2025-27696?
CVE-2025-27696 is considered a critical severity vulnerability due to its potential for unauthorized ownership takeover.
2
How do I fix CVE-2025-27696?
To fix CVE-2025-27696, upgrade to Apache Superset version 4.1.2 or later.
3
Who is affected by CVE-2025-27696?
Authenticated users with read permissions on Apache Superset versions through 4.1.1 are affected by CVE-2025-27696.
4
What is the impact of CVE-2025-27696?
The impact of CVE-2025-27696 allows authenticated users to take over ownership of dashboards, charts, or datasets.
5
What versions of Apache Superset are vulnerable to CVE-2025-27696?
Apache Superset versions through 4.1.1 are vulnerable to CVE-2025-27696.