Cross-site request forgery in Apache Zeppelin - CVE-2026-44613
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to perform actions on the victim's behalf.
The vulnerability exists due to cross-site request forgery in REST and WebSocket request handling when processing cross-origin state-changing requests with text/plain request bodies. A remote user can lure an authenticated user to a malicious site to perform actions on the victim's behalf.
User interaction is required for the victim to visit a malicious site while authenticated.