CVE-2026-44616

CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction

Vendor Apache Software Foundation
Product Apache Zeppelin
Weakness CWE-90 · LDAP injection
Published July 30, 2026
Last update July 30, 2026

CVSS base score

What the vulnerability does

01Description

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint                   and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which                   fixes this issue.

Key dates

02Disclosure timeline

July 30, 2026 CVE published