THREATOPS
THREAT OPSThreat News › CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition

CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition

medoss_secPublished 2026-07-30

<p>Posted by Jongyoul Lee on Jul 30</p>Severity: low <br /> <br /> Affected versions:<br /> <br /> - Apache Zeppelin 0.9.0 before 0.12.1<br /> <br /> Description:<br /> <br /> Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker <br /> with permission to rename a note, or access to folder operations, could supply traversal segments i

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/327