
A PoC/exploit has been discovered for vulnerability CVE-2026-23980 PT ID: PT-2026-21679 Vendor: Apache Software Foundation Product: Apache Superset Description: Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue. References: • https://dbu.gs/vulnerability/PT-2026-21679 • https://github.com/hyphentbg/cve-2026-23980
Post summary
The text reports a PoC/exploit reference for CVE-2026-23980 in Apache Superset and provides SQL injection details plus a fixed version. It recommends upgrading to 6.0.0 but does not report active exploitation or a false-positive claim.






