VDB
Sign up
HIGH8.9

PYSEC-2026-1161

Apache superset missing check for default SECRET_KEY

Quick fix

PYSEC-2026-1161 — apache-superset: upgrade to the fixed version with the command below.

pip install --upgrade 'apache-superset>=2.1.0'

Details

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/apache-superset
Introduced in: 0Fixed in: 2.1.0
Fixpip install --upgrade 'apache-superset>=2.1.0'

References