CVE-2026-23980Disclosure(apache / superset)

MEDIUMCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache superset systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • superset

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-28); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
superset

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-25: 1Mentions · 2026-02-28: 2Mentions · 2026-09-15: 1Mentions · 2026-09-16: 2Mentions · 2026-09-25: 1PoC Mentioned / Linked · 2026-09-15: 1PoC Mentioned / Linked · 2026-09-16: 2PoC Mentioned / Linked · 2026-09-25: 1Exploit Tool / Code · 2026-09-15: 1Exploit Tool / Code · 2026-09-16: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-09-15: 1Patch / Workaround · 2026-09-16: 1Patch / Workaround · 2026-09-25: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-28: 2Technical Details · 2026-09-15: 1Technical Details · 2026-09-16: 2Technical Details · 2026-09-25: 102-2502-2809-1509-1609-25
Signal classification4 categories
Disclosure
342.9%
PoC
228.6%
Patch
114.3%
Exploit
114.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-02-282
Disclosure2
2026-09-151
PoC1
2026-09-162
Disclosure1Exploit1
2026-09-251
PoC1
Full discourse7 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-23980 PT ID: PT-2026-21679 Vendor: Apache Software Foundation Product: Apache Superset Description: Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue. References: • https://dbu.gs/vulnerability/PT-2026-21679 • https://github.com/hyphentbg/cve-2026-23980

    Post summary

    The text reports a PoC/exploit reference for CVE-2026-23980 in Apache Superset and provides SQL injection details plus a fixed version. It recommends upgrading to 6.0.0 but does not report active exploitation or a false-positive claim.

    010721.1K
    3.6K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    5 CVEs fixed in Apache Superset CVE-2026-23969: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering https://www.openwall.com/lists/oss-security/2026/02/24/4 CVE-2026-23980: Improper Neutralization of Special Elements used in a SQL Command https://www.openwall.com/lists/oss-security/2026/02/24/5 + next tweet

    Post summary

    Apache Superset has released patches for five CVEs, including CVE-2026-23969 and CVE-2026-23980, addressing sensitive information exposure and SQL command neutralization issues.

    10020434
    4.4K followersView on X
  • iototsecnews@iototsecnews
    PoC

    Apache Superset の脆弱性 CVE-2026-23980:SQLi の PoC が登場 https://iototsecnews.jp/2026/09/16/apache-superset-sql-injection-flaw-gets-public-poc-exploit/ Apache Superset において、読み取り権限を持つ利用者が悪意あるクエリを挿入できる問題が発生しました。入力値の無害化処理の不備により、エラー応答を介した不当なデータ参照を引き起こす脆弱性 CVE-2026-23980 が存在します。実証コードが公に利用可能な状態となったため、知識の浅い攻撃者による悪用が容易となり、重要な情報資産への不正アクセスやデータの漏洩へとつながる恐れがあります。これに対する安全確保の手段として、該当する全環境の把握/アクセス権限の縮小/接続先データベースに対する権限の最小化/ログを用いた不審なエラー発生の監視/バージョン 6.0.0 以降へのアップデートの実施などが強く求められます。 #Apache #CVE202623980 #Superset #Vulnerability

    Post summary

    CVE-2026-23980 in Apache Superset features a SQLi vulnerability with a publicly available PoC; the text strongly recommends updating to version 6.0.0 or later as mitigation.

    00000139
    516 followersView on X
  • The Daily Tech Feed@dailytechonx
    Exploit

    Exploit released for Apache Superset SQL injection (CVE-2026-23980) puts read-only users at risk via sqlExpression/where params. Superset 6.0.0 fixes it — upgrade now. Keywords: Apache Superset SQL injection proof-of-concept exploit remediation users dashboards #ApacheSuperset #SQLInjection #CVE2026-23980 #DataSecurity #InfoSec #Cybersecurity https://thedailytechfeed.com/poc-reveals-critical-sql-injection-in-apache-superset-cve-2026-23980/

    Post summary

    The text reports that an exploit/PoC has been released for CVE-2026-23980, an Apache Superset SQL injection affecting read-only users via sqlExpression/where parameters. It also states Superset 6.0.0 fixes the issue and urges users to upgrade, but it does not report active exploitation in the wild.

    0000075
    737 followersView on X
  • CSIRT TELCONET@CSIRT_Telconet
    Disclosure

    Apache Superset (CVE-2026-23980) presenta una vulnerabilidad de inyección SQL en versiones anteriores a la 6.0.0 que permite a usuarios con permisos de lectura ejecutar consultas arbitrarias para comprometer la base de datos. Mas información: https://csirt.telconet.net/comunicacion/boletines-servicios/vulnerabilidad-de-inyeccion-sql-en-apache-superset-con-exploit-publico-disponible/ https://t.co/1NXlfqWaJ1

    Post summary

    Apache Superset CVE-2026-23980 is an SQL injection flaw in versions before 6.0.0 allowing read-permission users to execute arbitrary queries and compromise the database, with a public exploit referenced in a linked bulletin.

    00000110
    868 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23980 Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to … https://www.cve.org/CVERecord?id=CVE-2026-23980 ----- Traducción: CVE-2026-23980 Neu… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-23980, a SQL injection vulnerability in Apache Superset, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000045
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23980 Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to … https://www.cve.org/CVERecord?id=CVE-2026-23980

    Post summary

    The text announces CVE-2026-23980, a SQL injection vulnerability in Apache Superset that allows authenticated users with read access to exploit the flaw.

    00000320
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachesuperset---

Explore more