CVE-2026-33175Patch(jupyter / oauthenticator)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jupyter oauthenticator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oauthenticator

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
oauthenticator

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 104-0304-04
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-031
Patch1
2026-04-041
Disclosure1
Full discourse2 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33175 - High OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator a... https://www.thehackerwire.com/vulnerability/CVE-2026-33175/ https://t.co/GTEdzLNz0e

    Post summary

    The tweet announces an authentication bypass vulnerability in OAuthenticator prior to version 17.4.0, without mentioning PoC, exploit tools, or active exploitation.

    0000041
    164 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33175: HIGH] OAuthenticator software for JupyterHub patched an authentication bypass vulnerability pre-version 17.4.0, securing against unauthorized logins via unverified email on Auth0 tenant.#cve,CVE-2026-33175,#cybersecurity https://cvefind.com/CVE-2026-33175

    Post summary

    OAuthenticator for JupyterHub released a patch (v17.4.0) that fixes the authentication bypass vulnerability CVE‑2026‑33175, preventing unauthorized logins via unverified Auth0 emails.

    0000038
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjupyteroauthenticator---

Explore more