THREATOPS
THREAT OPSThreat News › CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification

CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification

medoss_secPublished 2026-07-30

<p>Posted by Daniel Gaspar on Jul 30</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache Superset 0.0.0 before 6.0.0<br /> <br /> Description:<br /> <br /> An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to <br /> update charts to modify dashboards they do not own. When updating a chart&apos;s properties via the REST

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/331