CVE-2026-23969Disclosure(apache / superset)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache superset systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was reported where the default list for the ClickHouse engine was incomplete. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • superset

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-28)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
superset

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-25: 1Mentions · 2026-02-28: 2Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-28: 202-2502-28
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-02-282
Disclosure2
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    5 CVEs fixed in Apache Superset CVE-2026-23969: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering https://www.openwall.com/lists/oss-security/2026/02/24/4 CVE-2026-23980: Improper Neutralization of Special Elements used in a SQL Command https://www.openwall.com/lists/oss-security/2026/02/24/5 + next tweet

    Post summary

    Apache Superset has released patches for five CVEs, including CVE-2026-23969 and CVE-2026-23980, addressing sensitive information exposure and SQL injection issues.

    10020434
    4.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23969 Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and char… https://www.cve.org/CVERecord?id=CVE-2026-23969 ----- Traducción: CVE-2026-23969 Apa… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-23969, noting that Apache Superset uses a configurable dictionary to restrict sensitive SQL functions, but provides no PoC, exploit, or patch details.

    0000040
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23969 Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and char… https://www.cve.org/CVERecord?id=CVE-2026-23969

    Post summary

    The CVE-2026-23969 vulnerability in Apache Superset involves the DISALLOWED_SQL_FUNCTIONS dictionary used to restrict execution of sensitive SQL functions in SQL Lab, but no PoC, exploit, patch, or active exploitation details are provided.

    00000289
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachesuperset---

Explore more