CVE-2023-27526: Apache Superset

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0. 

Affected products

  • Apache Superset: up to and including 2.1.0

Published 2023-09-06. Last modified 2026-06-17.