CVE-2026-44615: Path traversal in NotebookRepo note and folder path composition

Published Jul 31, 2026
·
Updated

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.                   Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved,                   written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

Affected Software

3 affected components
Apache Zeppelin>=0.9.0<=0.12.0
Apache Zeppelin=0.12.1
Apache Zeppelin>=0.9.0<0.12.1

Event History

Jul 31, 2026
CVE Published
via MITRE·11:05 AM
Data Sourced
via MITRE·11:05 AM
DescriptionWeakness
Data Sourced
via NVD·11:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-44615?

CVE-2026-44615 has a medium severity rating of 6.5 according to the CVSS 3.1 metrics.

2

How do I fix CVE-2026-44615?

To mitigate CVE-2026-44615, ensure that only trusted authenticated users have permission to rename notes or access folder operations in Apache Zeppelin.

3

What type of vulnerability is CVE-2026-44615?

CVE-2026-44615 is a path traversal vulnerability that affects Apache Zeppelin's FileSystemNotebookRepo configuration.

4

What could an attacker achieve by exploiting CVE-2026-44615?

An authenticated attacker could exploit CVE-2026-44615 to manipulate filesystem paths, potentially exposing sensitive files.

5

In which software is CVE-2026-44615 found?

CVE-2026-44615 is found in Apache Zeppelin, specifically when using the FileSystemNotebookRepo feature.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203