CVE Tools
Back to feed
Advisory Apache Zeppelin web-app Apache Software Foundation

CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions

OX Security·By Nir Zadok, Moshe Siman Tov Bustan··4 min read
CVE Tools coverage

OX Security researchers have disclosed a Cross-Site Request Forgery (CSRF) vulnerability affecting Apache Zeppelin, tracked as CVE-2026-44613. The flaw stems from a permissive default CORS configuration that accepted cross-origin, credentialed requests, alongside certain endpoints accepting plain-text bodies that bypassed standard preflight checks.

This combination allowed attackers to execute silent, unauthorized administrative actions against an authenticated user’s session simply by directing them to a malicious webpage. Apache has released version 0.12.1 to mitigate the issue, which restricts the allowed origins list by default and enforces strict content-type headers.

OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin

Vulnerability Details

CVE: CVE-2026-44613

Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints.…

Continue reading on OX Security

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store