SB2026082550 - Multiple vulnerabilities in Apache Zeppelin
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Cross-site request forgery (CVE-ID: CVE-2026-44613)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform actions on the victim's behalf.
The vulnerability exists due to cross-site request forgery in REST and WebSocket request handling when processing cross-origin state-changing requests with text/plain request bodies. A remote user can lure an authenticated user to a malicious site to perform actions on the victim's behalf.
User interaction is required for the victim to visit a malicious site while authenticated.
2) Path traversal (CVE-ID: CVE-2026-44615)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to write, move, or delete files and directories outside the notebook root.
The vulnerability exists due to path traversal in FileSystemNotebookRepo note and folder path composition when handling note rename or folder operations. A remote user can supply traversal segments in note or folder paths to write, move, or delete files and directories outside the notebook root.
Exploitation is possible only when FileSystemNotebookRepo is configured.
3) LDAP injection (CVE-ID: CVE-2026-44616)
CWE-ID: CWE-90 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose directory information.
The vulnerability exists due to improper neutralization of special elements in ldap queries in ActiveDirectoryGroupRealm filter construction when processing user-supplied input through the user-search endpoint. A remote user can inject ldap filter syntax to disclose directory information.
The role-lookup path is also affected after successful ldap authentication.
4) LDAP injection (CVE-ID: CVE-2026-44617)
CWE-ID: CWE-90 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to manipulate LDAP search filters.
The vulnerability exists due to improper neutralization of special elements in the LdapRealm component when constructing LDAP search filters. A remote user can supply specially crafted input to manipulate LDAP search filters.
This issue is due to the use of RFC 4514 distinguished-name escaping instead of RFC 4515 filter escaping.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=94trzcny14c1csgotsnkyrfsflt30b2c
- https://github.com/apache/zeppelin/pull/5229
- https://lists.apache.org/api/email.lua?id=ps1f0symnyxzq8c2dc3244v051jcwp40
- https://github.com/apache/zeppelin/pull/5227
- https://lists.apache.org/api/email.lua?id=p6llqpvcszpg1wc8kx5ncfkdbms3g0rn
- https://github.com/apache/zeppelin/pull/5226
- https://lists.apache.org/api/email.lua?id=s65t6n3s1v4j5b1w7zvv5w73ko69m1zv