SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-44613

MEDIUM · CVSS 6.1 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Apache Zeppelin versions 0.6.0 to 0.12.0 are vulnerable to a Cross-Site Request Forgery (CSRF) attack due to a permissive default CORS configuration that allows unauthorized cross-origin requests. This vulnerability can enable an attacker to execute actions on behalf of an authenticated user if they are tricked into visiting a malicious site. Organizations using affected versions should prioritize upgrading to version 0.12.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44613
Severity
MEDIUM
CVSS
6.1
EPSS
0.36%
Apache

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a                   malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)