ZeroHour
Organization

Apache

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Apache Superset SQL Injection Flaw Gets Public PoC Exploit

A public Python proof-of-concept exploit was released for CVE-2026-23980, an authenticated error-based SQL injection flaw in Apache Superset before 6.0.0.

A public proof-of-concept exploit repository now targets CVE-2026-23980, an error-based SQL injection affecting Apache Superset versions from 0.0.0 up to but not including 6.0.0. An authenticated user with read access can inject SQL through the sqlExpression or where parameters, potentially reaching business, customer, and security data depending on database configuration and privileges. Apache disclosed the flaw in February and urges upgrading to Superset 6.0.0; compensating controls include least-privilege database accounts, network restrictions, and log monitoring.

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass

Apache Airflow FAB provider flaw (CVE-2026-75156) lets attackers bypass Azure AD OAuth token validation via unvalidated issuer and audience claims.

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD id_tokens during OAuth login, enabling cross-tenant authentication bypass. The issue affects deployments where the FAB auth manager is configured with Azure AD as an OAuth provider. A fix is available in version 3.8.1. Severity is rated moderate.

oss-security · 7d agoVulnerabilityCVE-2026-75156

Related CVEs

  • Cross-tenant authentication bypass in Apache Airflow FAB provider
    CVE-2026-75156 is an origin-validation flaw (CWE-346) in the Apache Airflow FAB provider, which does not validate the issuer or audience of Azure AD id_tokens during OAuth login. It is triggered when the FAB auth manager is configured with Azure AD as the OAuth provider: because signing keys are fetched from Microsoft's multi-tenant JWKS endpoint, an id_token minted in any Azure tenant — including one the attacker registers — passes signature verification, and the username and role assignments in that attacker-controlled token are accepted. An attacker with no prior access to the deployment can therefore authenticate to the Airflow UI as an arbitrarily chosen user/role, gaining whatever access those assignments grant. Affected versions are 3.7.3 through 3.8.0, including every release containing the earlier CVE-2026-59243 signature-verification fix, so operators who already patched for that issue remain exposed and must upgrade again. No public proof-of-concept or known exploitation has been reported (EPSS 0.2%, not in CISA KEV).
    · Apache Airflow FAB provider (apache-airflow-providers-fab) — deployments using the FAB auth manager with Azure AD as OAuth prov 3.7.3 through 3.8.0 (fixed in 3.8.1)large
  • Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read acce
    Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.
    · apache superset PoC

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.