CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions
AdvisoryApache ZeppelinOur summary
OX Security researchers have disclosed a Cross-Site Request Forgery (CSRF) vulnerability affecting Apache Zeppelin, tracked as CVE-2026-44613. The flaw stems from a permissive default CORS configuration that accepted cross-origin, credentialed requests, alongside certain endpoints accepting plain-text bodies that bypassed standard preflight checks.
This combination allowed attackers to execute silent, unauthorized administrative actions against an authenticated user’s session simply by directing them to a malicious webpage. Apache has released version 0.12.1 to mitigate the issue, which restricts the allowed origins list by default and enforces strict content-type headers.
Below is the opening; the full story is at OX Security.
From OX Security
OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin
Vulnerability Details
CVE: CVE-2026-44613
Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.