Path Traversal Vulnerability in Apache Zeppelin
CVE-2026-44615

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
31 July 2026

What is CVE-2026-44615?

A path traversal vulnerability exists in Apache Zeppelin due to insufficient validation of user-supplied paths in the FileSystemNotebookRepo configuration. An authenticated attacker with permissions to rename a note or access folder operations can exploit this weakness by inserting traversal segments in note or folder paths. This exploitation can enable the manipulation of notebook files or directories, allowing them to be moved, altered, or deleted outside the designated notebook directory. Users should upgrade to version 0.12.1 or later to mitigate this vulnerability.

Affected Version(s)

Apache Zeppelin 0.9.0 < 0.12.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Green-m
.