LDAP Injection Affecting org.apache.zeppelin:zeppelin-server package, versions [0.6.0,0.12.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.45% (37th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about LDAP Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHEZEPPELIN-18507757
  • published2 Aug 2026
  • disclosed30 Jul 2026
  • creditUnknown

Introduced: 30 Jul 2026

NewCVE-2026-44616  (opens in a new tab)
CWE-90  (opens in a new tab)

How to fix?

Upgrade org.apache.zeppelin:zeppelin-server to version 0.12.1 or higher.

Overview

org.apache.zeppelin:zeppelin-server is a web-based notebook that enables interactive data analytics. You can make beautiful data-driven, interactive and collaborative documents with SQL, Scala and more.

Affected versions of this package are vulnerable to LDAP Injection through the searchForUserName and getRoleNamesForUser paths in ActiveDirectoryGroupRealm. An authenticated attacker can inject LDAP filter syntax by supplying crafted usernames or role-lookup input to the user-search endpoint or post-authentication role lookup, causing Zeppelin to build attacker-controlled search filters. This can be used to alter the LDAP query and expose directory information beyond the intended user record. In affected deployments, a malicious authenticated user can enumerate or retrieve unintended LDAP entries during login and group resolution.

CVSS Base Scores

version 4.0
version 3.1