LDAP Injection in Apache Zeppelin 0.6.00.12.0 (ADGroupRealm)
CVE-2026-44616 Published on July 30, 2026
Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Vulnerability Analysis
CVE-2026-44616 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a LDAP Injection Vulnerability?
The software constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
CVE-2026-44616 has been classified to as a LDAP Injection vulnerability or weakness.
Products Associated with CVE-2026-44616
Want to know whenever a new CVE is published for Apache Zeppelin? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Zeppelin:- Version 0.6.0 and below 0.12.1 is affected.