Advisory Apache Zeppelin web-app Apache Software Foundation
CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions
OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin
Vulnerability Details
CVE: CVE-2026-44613
Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints.…