Apache Superset: Incorrect authorization leading to resource ownership takeover
Vulnerability Description
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 4.1.2 or above, which fixes the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27696
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- João Marono
- Daniel Gaspar
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →