https://seclists.org/oss-sec/2026/q1/206: CVE-2026-23984: Apache Superset: SQLLab ad-Only Bypass on PostgSQL
Published Feb 24, 2026
·Updated
Affected Software
1 affected component
Apache Superset<6.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-23984?
CVE-2026-23984 is classified as a severity that can potentially lead to unauthorized data access due to improper input validation.
2
How do I fix CVE-2026-23984?
To fix CVE-2026-23984, upgrade Apache Superset to version 6.0.0 or later where the vulnerability has been addressed.
3
What versions of Apache Superset are affected by CVE-2026-23984?
Apache Superset versions before 6.0.0 are affected by CVE-2026-23984.
4
What does CVE-2026-23984 allow an attacker to do?
CVE-2026-23984 allows an authenticated user with SQLLab access to bypass read-only verification when using PostgreSQL.
5
Who is at risk from CVE-2026-23984?
Authenticated users with SQLLab access in Apache Superset prior to version 6.0.0 are at risk from CVE-2026-23984.