MEDIUMVulnerability

CVE-2026-44616

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint                   and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which                   fixes this issue.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-44616
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
published_at
2026-07-30T16:17:12.257
last_modified
2026-08-05T17:23:15.207

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-44616 — Ninja Signal Threat Intelligence | Ninja Signal