VDB
Sign up
MEDIUM4.3

PYSEC-2026-776

Apache Superset allows authenticated users to access metadata they have no permission to

Quick fix

PYSEC-2026-776 — apache-superset: upgrade to the fixed version with the command below.

pip install --upgrade 'apache-superset>=1.5.1'

Details

Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/apache-superset
Introduced in: 0Fixed in: 1.5.1
Fixpip install --upgrade 'apache-superset>=1.5.1'

References