Apache · Apache Zeppelin · CVE-2026-44617
**Name of the Vulnerable Software and Affected Versions**
Apache Zeppelin versions 0.11.1 through 0.12.0
**Description**
An LDAP filter injection issue exists in the `LdapRealm` component. The system incorrectly applied RFC 4514 distinguished-name escaping instead of RFC 4515 filter escaping when constructing LDAP search filters, which resulted in special filter characters being insufficiently escaped.
**Recommendations**
Upgrade to version 0.12.1.