9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2026-23980 - Apache Superset Authenticated SQL Injection / \ | | | | | || | \\\ sqlExpression goes straight to the query. no parameterization. no hope. Apache Superset ChartDataRestApi.data - QueryContext.getdfpayload - SqlaTable.getsqlaquery -...
Basic Information
ID
3A539A1A-788E-5AFF-A71F-59BAF5312536
Published
Apr 12, 2026 at 15:44
Modified
Apr 12, 2026 at 15:45