THREATOPS
THREAT OPSThreat News › CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling

CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling

medoss_secPublished 2026-07-30

<p>Posted by Jongyoul Lee on Jul 30</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Zeppelin 0.6.0 before 0.12.1<br /> <br /> Description:<br /> <br /> Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin <br /> state-changing requests and accepted text/plain request bodies, allowing an attacker who lur

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/326