SB2026082550 - Multiple vulnerabilities in Apache Zeppelin



SB2026082550 - Multiple vulnerabilities in Apache Zeppelin

Published: August 25, 2026

Security Bulletin ID SB2026082550
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 25% Low 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Cross-site request forgery (CVE-ID: CVE-2026-44613)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to perform actions on the victim's behalf.

The vulnerability exists due to cross-site request forgery in REST and WebSocket request handling when processing cross-origin state-changing requests with text/plain request bodies. A remote user can lure an authenticated user to a malicious site to perform actions on the victim's behalf.

User interaction is required for the victim to visit a malicious site while authenticated.


2) Path traversal (CVE-ID: CVE-2026-44615)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to write, move, or delete files and directories outside the notebook root.

The vulnerability exists due to path traversal in FileSystemNotebookRepo note and folder path composition when handling note rename or folder operations. A remote user can supply traversal segments in note or folder paths to write, move, or delete files and directories outside the notebook root.

Exploitation is possible only when FileSystemNotebookRepo is configured.


3) LDAP injection (CVE-ID: CVE-2026-44616)

CWE-ID: CWE-90 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose directory information.

The vulnerability exists due to improper neutralization of special elements in ldap queries in ActiveDirectoryGroupRealm filter construction when processing user-supplied input through the user-search endpoint. A remote user can inject ldap filter syntax to disclose directory information.

The role-lookup path is also affected after successful ldap authentication.


4) LDAP injection (CVE-ID: CVE-2026-44617)

CWE-ID: CWE-90 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to manipulate LDAP search filters.

The vulnerability exists due to improper neutralization of special elements in the LdapRealm component when constructing LDAP search filters. A remote user can supply specially crafted input to manipulate LDAP search filters.

This issue is due to the use of RFC 4514 distinguished-name escaping instead of RFC 4515 filter escaping.


Remediation

Install update from vendor's website.