CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Zeppelinto a version that resolves this vulnerability.Fixed in 0.12.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44616?
The severity of CVE-2026-44616 is medium with a CVSS score of 6.5.
How can I fix CVE-2026-44616?
To fix CVE-2026-44616, update to the latest version of Apache Zeppelin where the LDAP injection vulnerability has been addressed.
What type of vulnerability is CVE-2026-44616?
CVE-2026-44616 is an LDAP injection vulnerability that occurs due to improper handling of user-controlled input in Apache Zeppelin.
Who can be affected by CVE-2026-44616?
Authenticated users of Apache Zeppelin can be affected by CVE-2026-44616, as attackers can exploit the vulnerability through the user-search endpoint.
What information can be exposed by CVE-2026-44616?
CVE-2026-44616 can potentially expose directory information due to LDAP filter syntax injection.