CVE-2025-27696: Apache Superset

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 4.1.2 or above, which fixes the issue.

Affected products

  • Apache Superset: before 4.1.2 (fixed in 4.1.2)

Published 2025-05-13. Last modified 2026-06-17.