CVE-2026-44613 Details
Description
Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
A Cross-Site Request Forgery (CSRF) vulnerability exists in Apache Zeppelin versions 0.6.0 prior to 0.12.1. The issue arises from the default Cross-Origin Resource Sharing (CORS) configuration, which permitted cross-origin state-changing requests and accepted text/plain request bodies. This allowed an attacker to lure an authenticated user to a malicious site and perform actions on their behalf via REST and WebSocket endpoints.
Users are advised to upgrade to Apache Zeppelin version 0.12.1, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ox.security/blog/cve-2026-44613-turning-a-csrf-into-silent-unauthorized-actions/ | CVE | |
| http://www.openwall.com/lists/oss-security/2026/07/30/1 | CVE | Mailing ListThird Party Advisory |
| https://github.com/apache/zeppelin/pull/5229 | [email protected] | Issue TrackingPatch |
| https://lists.apache.org/thread/94trzcny14c1csgotsnkyrfsflt30b2c | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache zeppelin | >= 0.6.0, < 0.12.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CVE |
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
| Jul 30, 2026 | CVE Modified | CVE |