Public proof-of-concept exploit code is available for CVE-2026-23980, an authenticated error-based SQL injection vulnerability affecting Apache Superset versions before 6.0.0. An attacker with read-level access can submit crafted sqlExpression and where parameter values to trigger database errors, potentially exposing backend query details, database structure, and sensitive metadata.
Apache remediated the issue in Superset 6.0.0; organizations should upgrade affected deployments promptly. Security teams should also review low-privilege Superset accounts and inspect application, proxy, and database logs for malformed requests involving the affected parameters and anomalous database-error activity, as public exploit availability is likely to increase probing of unpatched internet-exposed instances.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2026-23980, an authenticated error-based SQL injection vulnerability affecting Apache Superset versions before 6.0.0, and remediated it in version 6.0.0. The flaw allows read-level users to manipulate the sqlExpression and where parameters to trigger database errors that may expose query and database metadata.
A public repository made a modified proof-of-concept exploit for CVE-2026-23980 available, including a Python exploit.py file. The sources state that public exploit availability lowers the effort needed to test exposed unpatched Superset instances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.