Path traversal in Apache Zeppelin - CVE-2026-44615
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to write, move, or delete files and directories outside the notebook root.
The vulnerability exists due to path traversal in FileSystemNotebookRepo note and folder path composition when handling note rename or folder operations. A remote user can supply traversal segments in note or folder paths to write, move, or delete files and directories outside the notebook root.
Exploitation is possible only when FileSystemNotebookRepo is configured.