SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-44617

MEDIUM · CVSS 6.5 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0 are vulnerable to an LDAP filter injection due to improper escaping of special characters in LDAP search filters. This vulnerability could allow attackers to manipulate LDAP queries, potentially leading to unauthorized access or data exposure. Organizations using affected versions should prioritize upgrading to version 0.12.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44617
Severity
MEDIUM
CVSS
6.5
EPSS
0.52%
Apache

Original NVD Description

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.                   This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)