CVE-2026-44616

Source
https://cve.org/CVERecord?id=CVE-2026-44616
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44616.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44616
Published
2026-07-30T15:21:21.609Z
Modified
2026-08-12T03:51:27.190275411Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Details

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint                   and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which                   fixes this issue.

Database specific
{
    "cna_assigner": "apache",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44616.json",
    "cwe_ids": [
        "CWE-90"
    ]
}
References

Affected packages

Git / github.com/apache/zeppelin

Affected ranges

Type
GIT
Repo
https://github.com/apache/zeppelin
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "cpe": "cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.6.0"
        },
        {
            "fixed": "0.12.1"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44616.json"