VYPR
Medium severity6.5NVD Advisory· Published Jul 30, 2026· Updated Aug 5, 2026

CVE-2026-44617

CVE-2026-44617

Description

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.                   This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Apache/Zeppelinllm-fuzzy2 versions
    <0.12.1+ 1 more
    • (no CPE)range: <0.12.1
    • cpe:2.3:a:apache:zeppelin:*:*:*:*:*:*:*:*range: >=0.11.1,<0.12.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.