Apache Superset Sensitive Data Exposure Vulnerability in Tag Endpoint

Vulnerability

A sensitive data exposure vulnerability has been identified in Apache Superset versions prior to 6.0.0. This issue allows authenticated users, particularly those with low privileges such as the Gamma role, to access sensitive user information. The vulnerability arises in the Tag endpoint, which is disabled by default. When enabled, this endpoint can be used to retrieve a list of objects associated with a specific tag. If the associated objects include users, the API response improperly exposes sensitive fields such as password hashes (using the pbkdf2 algorithm), email addresses, and login statistics. This flaw enables unauthorized access to sensitive authentication data.

Impact

Exploitation of this vulnerability allows authenticated users with low privileges to access sensitive user information, including password hashes, email addresses, and login statistics.

Remediation

Users are advised to upgrade to Apache Superset version 6.0.0 or later, which addresses this vulnerability. Alternatively, ensure that the TAGGING_SYSTEM configuration is set to False, which is the current default.

Added: Feb 24, 2026, 3:00 PM
Updated: Feb 24, 2026, 11:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.