A vulnerability classified as problematic has been found in Apache Zeppelin up to 0.12.0. Affected is an unknown function of the component CORS Configuration. The manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-44613. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.