CVE-2026-23981: An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updati
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards) to associate the chart with. The validation logic in the UpdateChartCommand failed to verify that the user had write permissions for the target dashboards specified in the request body.
This issue affects Apache Superset: before 6.0.0.
Users are recommended to upgrade to version 6.0.0, which fixes the issue.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-23981
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-239810.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-23981 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for An Improper Authorization
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-14538: An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-s…nvd · 2026-07-31
- highCVE-2026-58222: A security flaw combining LDAP filter injection and improper authorization checks was found in…nvd · 2026-07-30
- mediumCVE-2026-66751: Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows an…nvd · 2026-07-28
- mediumCVE-2026-61487: Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache Ac…nvd · 2026-07-28
- criticalCVE-2026-62835: Improper authorization in Azure Portal allows an unauthorized attacker to disclose information…nvd · 2026-07-24
- criticalCVE-2026-56160: Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to eleva…nvd · 2026-07-24
More from NVD Recent CVEs
- mediumCVE-2026-6453: The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to …2026-08-01
- mediumCVE-2026-18435: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…2026-08-01
- mediumCVE-2026-18344: The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site …2026-08-01
- mediumCVE-2026-18062: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…2026-08-01
- mediumCVE-2026-18059: The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to…2026-08-01