Path traversal in Apache Zeppelin - CVE-2026-44615

 

Path traversal in Apache Zeppelin - CVE-2026-44615

Published: August 25, 2026


Vulnerability identifier: #VU145154
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44615
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to write, move, or delete files and directories outside the notebook root.

The vulnerability exists due to path traversal in FileSystemNotebookRepo note and folder path composition when handling note rename or folder operations. A remote user can supply traversal segments in note or folder paths to write, move, or delete files and directories outside the notebook root.

Exploitation is possible only when FileSystemNotebookRepo is configured.


Affected software

Apache Zeppelin

How to mitigate CVE-2026-44615

Install security update from vendor's website.

Apache Zeppelin - update to 0.12.1

External References

Related Security Bulletins