CVE-2026-44613
CVE-2026-44613 is a medium-severity vulnerability in Apache Zeppelin with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-352.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- EPSS exploit prediction: 0% (32nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-352
- Affected product: Apache Zeppelin
- Published:
- Last modified:
Description
Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Frequently asked questions
- What is CVE-2026-44613?
- Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
- How severe is CVE-2026-44613?
- CVE-2026-44613 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-44613 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (32nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-44613?
- CVE-2026-44613 affects Apache Zeppelin. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-44613?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-44613 published?
- CVE-2026-44613 was published on 2026-07-30 and last updated on 2026-08-07.
References
- https://github.com/apache/zeppelin/pull/5229
- https://lists.apache.org/thread/94trzcny14c1csgotsnkyrfsflt30b2c
- http://www.openwall.com/lists/oss-security/2026/07/30/1
- https://www.ox.security/blog/cve-2026-44613-turning-a-csrf-into-silent-unauthorized-actions/
Affected products (1)
- cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Zeppelin
- CVE-2024-31866 — Critical (CVSS 9.8): Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or…
- CVE-2024-31864 — Critical (CVSS 9.8): Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject…
- CVE-2019-10095 — Critical (CVSS 9.8): bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark…
- CVE-2018-1317 — High (CVSS 8.8): In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as…
- CVE-2017-12619 — High (CVSS 8.1): Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user…
- CVE-2024-41169 — High (CVSS 7.5): The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources,…
All CVEs affecting Apache Zeppelin →
Other CWE-352 (Cross-Site Request Forgery (CSRF)) vulnerabilities
- CVE-2025-32642 — Critical (CVSS 10.0): Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This…
- CVE-2025-23922 — Critical (CVSS 10.0): Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a…
- CVE-2017-5145 — Critical (CVSS 10.0): An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware…
- CVE-2019-25729 — Critical (CVSS 9.8): PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute…
- CVE-2025-48340 — Critical (CVSS 9.8): Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows…
- CVE-2025-2907 — Critical (CVSS 9.8): The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing…
Browse all CWE-352 (Cross-Site Request Forgery (CSRF)) vulnerabilities →