CSRF Vulnerability in Apache Zeppelin Affects Multiple Versions by Apache
CVE-2026-44613

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 July 2026

What is CVE-2026-44613?

A cross-site request forgery (CSRF) vulnerability was identified in Apache Zeppelin that could allow an attacker to impersonate authenticated users. The vulnerability arises due to the application's default CORS configuration, which permits cross-origin state-changing requests. By enticing a user to visit a malicious site, an attacker can exploit this flaw to perform unauthorized actions via REST and WebSocket endpoints. This affects multiple versions of Apache Zeppelin, specifically from 0.6.0 to 0.12.0, and users are advised to upgrade to version 0.12.1 to mitigate the risk.

Affected Version(s)

Apache Zeppelin 0.6.0 < 0.12.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reza (HazardLab Ninja) and Nir Zadok
.