LDAP injection in Apache Zeppelin - CVE-2026-44617
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to manipulate LDAP search filters.
The vulnerability exists due to improper neutralization of special elements in the LdapRealm component when constructing LDAP search filters. A remote user can supply specially crafted input to manipulate LDAP search filters.
This issue is due to the use of RFC 4514 distinguished-name escaping instead of RFC 4515 filter escaping.