6.5

CVE-2026-44616

Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint                   and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which                   fixes this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Zeppelin Version >= 0.6.0 < 0.12.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.369
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.5 1.2 5.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

https://github.com/apache/zeppelin/pull/5226
Patch
Issue Tracking
https://lists.apache.org/thread/p6llqpvcszpg1wc8kx5ncfkdbms3g0rn
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2026/07/30/3
Third Party Advisory
Mailing List