CVE-2026-23981
Last modified
CVE-2026-23981 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards) to associate the chart with. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards) to associate the chart with. The validation logic in the UpdateChartCommand failed to verify that the user had write permissions for the target dashboards specified in the request body. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Superset | < 6.0.0 |
References
- https://lists.apache.org/thread/k7q9z27t901xvqnkwgyns1l7w1dj3csfMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/30/6Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23981?
How severe is CVE-2026-23981?
How do I fix CVE-2026-23981?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23976Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2026-23977Missing Authorization vulnerability in WPFactory Helpdesk Su…7.5
- CVE-2026-23978Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2026-23979Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-2398Authorization bypass through User-Controlled key vulnerabili…8.8
- CVE-2026-23980Improper Neutralization of Special Elements used in a SQL Co…6.5
- CVE-2026-23982An Improper Authorization vulnerability exists in Apache Sup…6.5
- CVE-2026-23983A Sensitive Data Exposure vulnerability exists in Apache Sup…6.5
- CVE-2026-23984An Improper Input Validation vulnerability exists in Apache …6.5
- CVE-2026-23985A Regular Expression Denial of Service (ReDoS) vulnerability…6.5
- CVE-2026-23986Copier is a library and CLI app for rendering project templa…7.1
- CVE-2026-23988Rufus is a utility that helps format and create bootable USB…7
Are you affected by CVE-2026-23981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
