MEDIUM4.3
PYSEC-2026-1188
Apache Superset has Incorrect Default Permissions
Quick fix
PYSEC-2026-1188 — apache-superset: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-superset>=2.1.2'Details
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/apache-superset
Introduced in:
0Fixed in: 2.1.2Fix
pip install --upgrade 'apache-superset>=2.1.2'References
- https://nvd.nist.gov/vuln/detail/CVE-2023-42501[ADVISORY]
- https://github.com/apache/superset[PACKAGE]
- https://lists.apache.org/thread/vk1rmrh9kz0chjmc9tk7o3md6zpz4ygh[WEB]
- http://www.openwall.com/lists/oss-security/2023/11/27/3[WEB]
- https://pypi.org/project/apache-superset[PACKAGE]
- https://github.com/advisories/GHSA-vv65-fjfj-4736[ADVISORY]