30
30
30
30
45
45
45
30
45
30
45
45
30
30
Public PoC Released for Apache Superset SQL Injection Vulnerability
A public Python PoC exploit is available for CVE-2026-23980, an authenticated error-based SQL injection in Apache Superset versions before 6.0.0.
CVE-2026-23980 is a SQL injection flaw (CWE-89) in Apache Superset affecting all releases before 6.0.0, exploitable via the sqlExpression and where parameters by authenticated users with read-level access. A public repository containing a Python exploit.py proof-of-concept has been released, reducing attacker effort against exposed instances. Apache disclosed the issue on February 24, 2026 and fixed it in Superset 6.0.0. Defenders should upgrade and monitor logs for malformed queries, database errors, and unusual activity from low-privilege accounts.
45
35
45
45
30
30
45
30
You're deploying it wrong! TeamCity, Subversion & Web Deploy part 4: Continuous builds with TeamCity
30
30
Attackers can siphon data from Splunk Enterprise if an authenticated user visits a malicious webpage
50
30
35
30
30
45
30
45
30
30
45
30
45
30
45
30