# CVE-2026-44616

## Summary

- **CVE ID:** CVE-2026-44616
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-90
- **Published:** Jul 30, 2026
- **Last Modified:** Jul 31, 2026

## Description

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint                   and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which                   fixes this issue.

## Affected Products

- Apache Software Foundation — Apache Zeppelin (0.6.0)

## References

- [CNA](https://github.com/apache/zeppelin/pull/5226)
- [CNA](https://lists.apache.org/thread/p6llqpvcszpg1wc8kx5ncfkdbms3g0rn)
- [CVE](http://www.openwall.com/lists/oss-security/2026/07/30/3)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 37.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._