CVE Tools

CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions

OX SecurityBy Nir Zadok, Moshe Siman Tov Bustan4 min read

AdvisoryApache Zeppelin

Our summary

OX Security researchers have disclosed a Cross-Site Request Forgery (CSRF) vulnerability affecting Apache Zeppelin, tracked as CVE-2026-44613. The flaw stems from a permissive default CORS configuration that accepted cross-origin, credentialed requests, alongside certain endpoints accepting plain-text bodies that bypassed standard preflight checks.

This combination allowed attackers to execute silent, unauthorized administrative actions against an authenticated user’s session simply by directing them to a malicious webpage. Apache has released version 0.12.1 to mitigate the issue, which restricts the allowed origins list by default and enforces strict content-type headers.

Read at OX Security

Below is the opening; the full story is at OX Security.

From OX Security

OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin

Vulnerability Details

CVE: CVE-2026-44613

Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints.…

Continue at OX Security

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store