Critical Auth Bypass and RCE Vulnerability in Apache Superset

Critical Auth Bypass and RCE Vulnerability in Apache Superset

First seen 10 Sep 2026, 02:15 UTC Sploitus 72.8

Article Content

Browse articles
ThreatCluster

Apache Superset has been found to have a critical security vulnerability, CVE-2023-27524, that allows for authentication bypass and remote code execution (RCE). This flaw arises from a default insecure configuration, specifically a predictable Flask secret key, affecting numerous instances of Superset. Attackers can exploit this vulnerability to gain administrative privileges, access user credentials, and compromise sensitive data. The vulnerability impacts all Superset versions up to 2.0.1 if the default SECRET_KEY has not been changed. A proof-of-concept exploit has been developed, demonstrating the ability to validate the vulnerability and execute commands on the server. Organizations using Apache Superset are urged to update their configurations and apply necessary patches to mitigate this risk. The vulnerability was first disclosed on April 24, 2023, and has been actively exploited since January 2024. The situation remains critical for unpatched installations.

Key Points: • CVE-2023-27524 allows for authentication bypass and RCE in Apache Superset. • The vulnerability affects all Superset versions up to 2.0.1 with default SECRET_KEY. • Active exploitation has been confirmed, necessitating immediate action from affected organizations.

Ask AI about this cluster

Timeline

2020-06-19
CVE-2020-9495 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-04-24
CVE-2023-27524 published
Apache disclosed a critical authentication bypass and RCE vulnerability in Superset.
Sploitus
2023-04-25
First public PoC released
A proof-of-concept exploit demonstrating the vulnerability was made publicly available.
Sploitus
2024-01-08
CVE-2023-27524 added to CISA KEV
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.
Sploitus
2026-09-07
Exploitation details published
Details on how to exploit CVE-2023-27524 were shared, emphasizing the need for immediate remediation.
Sploitus