What is CVE-2026-23981?
An authenticated user with chart update permissions in Apache Superset can modify dashboards they do not own by associating charts via the REST API. This issue stems from improper authorization checks. Affected users should immediately update Apache Superset to the patched version.
Azərbaycanca: Apache Superset-də səlahiyyətli istifadəçi REST API vasitəsilə qrafik yeniləyərkən sahib olmadığı dashboard-lara qrafik əlavə edə bilir. Bu zəiflik 'Improper Authorization'dan qaynaqlanır. Təsirlənən istifadəçilər dərhal Apache Superset-i yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Apache
FAQ1
What can an attacker exploiting CVE-2026-23981 in Apache Superset do?
An authenticated user with chart update permissions can modify dashboards they do not own by associating charts via the REST API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.