Apache Software Foundation: Public PoC Released for Apache Superset SQL Injection Vulnerability

Apache Software Foundation: Public PoC Released for Apache Superset SQL Injection Vulnerability

Public PoC Exploit Released for Critical Apache Superset SQL Injection Flaw (CVE-2026-23980)

A proof-of-concept (PoC) exploit has been made public for CVE-2026-23980, a high-severity SQL injection vulnerability in Apache Superset versions prior to 6.0.0. The flaw allows authenticated users with read-level access to execute error-based SQL injection by manipulating the sqlExpression and where parameters in the application.

Apache Superset, a widely used open-source data visualization and business intelligence platform, connects to enterprise databases, making this vulnerability particularly concerning for organizations exposing Superset instances to multiple users. Successful exploitation could enable attackers to extract sensitive details such as database structure, table names, and column data potentially facilitating further unauthorized access or data inference.

The vulnerability, classified as an Improper Neutralization of Special Elements in SQL Commands, affects all Superset releases from 0.0.0 up to (but not including) 6.0.0. Apache has patched the issue in version 6.0.0, urging users to upgrade immediately. Security researchers have also published a Python-based PoC exploit (exploit.py), increasing the risk of exploitation as attackers can now test vulnerable environments with minimal effort.

The flaw was discovered by Pritam Chakkerwar, reported by Dhanush Nayak, and remediated by Pedro Sousa. Apache disclosed the vulnerability in a security advisory on February 24, 2026.

Organizations running affected versions should identify all Superset instances, verify installed versions, and prioritize upgrades. Administrators are advised to review user permissions, particularly for accounts with read access to dashboards and datasets, and monitor logs for suspicious activity such as malformed queries, database errors, or unusual requests targeting the vulnerable parameters. While exploitation requires authentication, even low-privilege access can pose significant risks in data analytics platforms.

Source: https://cybersecuritynews.com/poc-apache-superset-sql-injection/

The Apache Software Foundation cybersecurity rating report: https://www.rankiteo.com/company/the-apache-software-foundation

"id": "THE1789547025",
"linkid": "the-apache-software-foundation",
"type": "Vulnerability",
"date": "2/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Software',
                        'name': 'Apache Superset',
                        'type': 'Open-source data visualization and business '
                                'intelligence platform'}],
 'attack_vector': 'Authenticated user manipulation of `sqlExpression` and '
                  '`where` parameters',
 'data_breach': {'sensitivity_of_data': 'High (potential for unauthorized '
                                        'access or data inference)',
                 'type_of_data_compromised': 'Database structure, table names, '
                                             'column data, and sensitive '
                                             'details'},
 'date_publicly_disclosed': '2026-02-24',
 'description': 'A proof-of-concept (PoC) exploit has been made public for '
                'CVE-2026-23980, a high-severity SQL injection vulnerability '
                'in Apache Superset versions prior to 6.0.0. The flaw allows '
                'authenticated users with read-level access to execute '
                'error-based SQL injection by manipulating the `sqlExpression` '
                'and `where` parameters in the application. Successful '
                'exploitation could enable attackers to extract sensitive '
                'details such as database structure, table names, and column '
                'data, potentially facilitating further unauthorized access or '
                'data inference.',
 'impact': {'data_compromised': 'Database structure, table names, column data, '
                                'and sensitive details',
            'systems_affected': 'Apache Superset instances (versions < 6.0.0)'},
 'post_incident_analysis': {'corrective_actions': 'Patch to version 6.0.0, '
                                                  'review user permissions, '
                                                  'enhance monitoring',
                            'root_causes': 'Improper Neutralization of Special '
                                           'Elements in SQL Commands'},
 'recommendations': 'Identify all Superset instances, verify installed '
                    'versions, prioritize upgrades, review user permissions, '
                    'and monitor logs for suspicious activity.',
 'references': [{'source': 'Apache Security Advisory'},
                {'source': 'PoC Exploit (exploit.py)'}],
 'response': {'containment_measures': 'Upgrade to Apache Superset version '
                                      '6.0.0',
              'enhanced_monitoring': 'Monitor logs for malformed queries, '
                                     'database errors, or unusual requests',
              'remediation_measures': 'Review user permissions, monitor logs '
                                      'for suspicious activity'},
 'title': 'Public PoC Exploit Released for Critical Apache Superset SQL '
          'Injection Flaw (CVE-2026-23980)',
 'type': 'SQL Injection',
 'vulnerability_exploited': 'CVE-2026-23980 (Improper Neutralization of '
                            'Special Elements in SQL Commands)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.