CVE Tools
Back to feed
Advisory Apache Zeppelin web-app Apache Software Foundation

CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions

OX Security·By Nir Zadok, Moshe Siman Tov Bustan··4 min read

OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin

Vulnerability Details

CVE: CVE-2026-44613

Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints.…

Continue reading on OX Security