What is CVE-2026-44617?
CVE-2026-44617 is an LDAP filter injection vulnerability in Apache Zeppelin's LdapRealm component. Due to using RFC 4514 distinguished-name escaping instead of proper RFC 4515 filter escaping when constructing LDAP search filters, special filter characters remain insufficiently escaped. Users should upgrade to the latest patched version of Apache Zeppelin.
Azərbaycanca: CVE-2026-44617 Apache Zeppelin-in LdapRealm komponentində LDAP filter injection zəifliyidir. Bu qüsur RFC 4515 standartına uyğun filter escaping əvəzinə səhvən RFC 4514 distinguished-name escaping istifadə edildiyi üçün xüsusi simvolların kifayət qədər qorunmamasına səbəb olur. İstifadəçilər Apache Zeppelin-i ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Apache
FAQ2
Which component of Apache Zeppelin is affected by CVE-2026-44617?
This vulnerability affects the LdapRealm component of Apache Zeppelin.
What causes the CVE-2026-44617 vulnerability?
It is caused by using RFC 4514 distinguished-name escaping instead of proper RFC 4515 filter escaping when constructing LDAP search filters, leaving special filter characters insufficiently escaped.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.