LDAP injection in Apache Zeppelin - CVE-2026-44616
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose directory information.
The vulnerability exists due to improper neutralization of special elements in ldap queries in ActiveDirectoryGroupRealm filter construction when processing user-supplied input through the user-search endpoint. A remote user can inject ldap filter syntax to disclose directory information.
The role-lookup path is also affected after successful ldap authentication.