CVE-2026-33175 details a high-severity authentication bypass vulnerability in OAuthenticator, a component integrating OAuth2 identity providers with JupyterHub, affecting versions prior to 17.4.0. This flaw permits an attacker with an unverified email address on an Auth0 tenant to log into JupyterHub, potentially leading to account takeover if email is used as the username claim. With a CVSS score of 8.8, the vulnerability has a network attack vector, low complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are public exploit modules available, though the vulnerability has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.4.0CPE matchmatch criteria | cpe:2.3:a:jupyter:oauthenticator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.