CVE-2026-44616
ANALYSIS PENDINGApache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Title source: cnaDescription
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/p6llqpvcszpg1wc8kx5ncfkdbms3g0rn
Details
CWE
CWE-90
Status
published
Products (1)
Apache Software Foundation/Apache Zeppelin
0.6.0 - 0.12.1
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026