Vulnerabilities

CISA Warns of Apache Superset Vulnerability Exploitation

CISA has added a critical-severity Apache Superset flaw (CVE-2023-27524) to its Known Exploited Vulnerabilities catalog.

CISA has added a critical-severity Apache Superset flaw (CVE-2023-27524) to its Known Exploited Vulnerabilities catalog.

The US cybersecurity agency CISA on Monday announced that it has added six more entries to its Known Exploited Vulnerabilities (KEV) catalog, including an Apache Superset bug disclosed in April 2023.

Apache Superset is an open source application written in Python that allows users to explore and visualize large amounts of data.

Superset is based on the Flask web framework and it relies on session cookies signed with a secret key for authentication.

The secret key is meant to be randomly generated but, in April last year, penetration testing firm Horizon3.ai warned that, upon installation, Superset would default the key to a specific value and that roughly 2,000 Superset instances accessible from the internet were using the default key.

An attacker could use the default session key to log in as an administrator to these Superset instances, access the databases connected to the application, tamper with them, and execute code remotely.

“By default, database connections are set up with read-only permissions but an attacker with admin access can enable writes and DML (data model language) statements. The powerful SQL Lab interface allows attackers to run arbitrary SQL statements against connected databases,” Horizon3.ai said.

Advertisement. Scroll to continue reading.

The issue was initially discovered in 2021, with the secret key value rotated in 2022 to a new default, and a warning added to the logs. Superset version 2.1 resolves the bug, now tracked as CVE-2023-27524, by preventing the server from starting if the secret key value is the default one.

With CISA adding the vulnerability to the KEV catalog, it means that threat actors have started exploiting it in the wild. The agency, however, does not provide specific details on the observed attacks.

CISA also added to KEV two recently resolved Adobe ColdFusion flaws (CVE-2023-38203 and CVE-2023-29300), a code execution bug in Apple products (CVE-2023-41990), an improper access check issue in Joomla (CVE-2023-23752), and a command injection issue in D-Link DSL-2750B devices (CVE-2016-20017).

The Binding Operational Directive (BOD) 22-01 requires that federal agencies identify vulnerable products within their networks and apply available patches and mitigations within 21 days after a vulnerability is added to CISA’s KEV list.

While BOD 22-01 only applies to federal agencies, all organizations are encouraged to review the KEV catalog and prioritize patching for the vulnerabilities in it, or discontinue the use of the impacted products where mitigations are not available.

Related: CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability

Related: CISA Warns of Old JBoss RichFaces Vulnerability Being Exploited in Attacks

Related: 557 CVEs Added to CISA’s Known Exploited Vulnerabilities Catalog in 2022

Related Content

Vulnerabilities

The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. 

Artificial Intelligence

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.

Vulnerabilities

The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations.

Vulnerabilities

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality.

Ransomware

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.

Vulnerabilities

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.

Vulnerabilities

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.

Vulnerabilities

The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version