CVE-2026-44617: CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') in Apache Software Foundation Apache Zeppelin
Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0 contain an LDAP filter injection vulnerability due to improper escaping of special characters in LDAP search filters. The vulnerability arises because LdapRealm uses RFC 4514 distinguished-name escaping instead of the correct RFC 4515 filter escaping, resulting in insufficient escaping of special filter characters. This issue is an incomplete fix of a previous vulnerability (CVE-2024-31867). Upgrading to version 0.12.1 addresses this vulnerability.
AI Analysis
Technical Summary
CVE-2026-44617 is an LDAP injection vulnerability in Apache Zeppelin caused by improper neutralization of special elements in LDAP search filters. The LdapRealm component incorrectly applies RFC 4514 distinguished-name escaping when constructing LDAP filters instead of the required RFC 4515 filter escaping. This leads to insufficient escaping of special characters in LDAP filters, potentially allowing injection attacks. The vulnerability affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Version 0.12.1 includes a fix that properly escapes LDAP filter characters, mitigating the issue. This vulnerability is a partial regression of CVE-2024-31867.
Potential Impact
The vulnerability allows an attacker to manipulate LDAP search filters due to improper escaping of special characters. This could lead to unauthorized LDAP queries or bypass of intended access controls if exploited. However, no known exploits are reported in the wild at this time.
Mitigation Recommendations
Users should upgrade Apache Zeppelin to version 0.12.1, which fixes the LDAP injection vulnerability by correctly escaping special characters in LDAP filters. No other mitigation or temporary workaround is indicated. Patch status is not explicitly confirmed in the input data, but the vendor recommends upgrading to 0.12.1 to address the issue.
CVE-2026-44617: CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') in Apache Software Foundation Apache Zeppelin
Description
Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0 contain an LDAP filter injection vulnerability due to improper escaping of special characters in LDAP search filters. The vulnerability arises because LdapRealm uses RFC 4514 distinguished-name escaping instead of the correct RFC 4515 filter escaping, resulting in insufficient escaping of special filter characters. This issue is an incomplete fix of a previous vulnerability (CVE-2024-31867). Upgrading to version 0.12.1 addresses this vulnerability.
Affected software
pkg:maven/org.apache.zeppelin/zeppelinRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44617 is an LDAP injection vulnerability in Apache Zeppelin caused by improper neutralization of special elements in LDAP search filters. The LdapRealm component incorrectly applies RFC 4514 distinguished-name escaping when constructing LDAP filters instead of the required RFC 4515 filter escaping. This leads to insufficient escaping of special characters in LDAP filters, potentially allowing injection attacks. The vulnerability affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Version 0.12.1 includes a fix that properly escapes LDAP filter characters, mitigating the issue. This vulnerability is a partial regression of CVE-2024-31867.
Potential Impact
The vulnerability allows an attacker to manipulate LDAP search filters due to improper escaping of special characters. This could lead to unauthorized LDAP queries or bypass of intended access controls if exploited. However, no known exploits are reported in the wild at this time.
Mitigation Recommendations
Users should upgrade Apache Zeppelin to version 0.12.1, which fixes the LDAP injection vulnerability by correctly escaping special characters in LDAP filters. No other mitigation or temporary workaround is indicated. Patch status is not explicitly confirmed in the input data, but the vendor recommends upgrading to 0.12.1 to address the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-05-07T07:50:20.046Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6bbb7a9c2644c7f8ad24c5
Added to database: 07/30/2026, 21:00:42 UTC
Last enriched: 07/30/2026, 21:01:02 UTC
Last updated: 07/30/2026, 21:12:13 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.