CVE-2026-44616
LDAP injection vulnerability in Apache Zeppelin.
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-90
- Affected
- apache/zeppelin
- Source
- security@apache.org
References
- https://github.com/apache/zeppelin/pull/5226Issue Tracking, Patch
- https://lists.apache.org/thread/p6llqpvcszpg1wc8kx5ncfkdbms3g0rnMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/30/3Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.