CVE-2026-33175 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 3, 2026
OAuthenticator - Authentication Bypass
Overview
OAuthenticator < 17.4.0 contains an authentication bypass caused by unverified email addresses on Auth0 tenants when email is used as username_claim, letting attackers login and potentially take over accounts, exploit requires unverified email on Auth0.
Severity & Score
Impact
Attackers can bypass authentication and take over user accounts, leading to unauthorized access.
Mitigation
Update to version 17.4.0 or later.
References
Social Media Activity(1 post)
š CVE-2026-33175 - High (8.8) OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an... š https://www.thehackerwire.com/vulnerability/CVE-2026-33175/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-33175
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_authentication
- Status
- new
- EPSS
- 9.8%
- Social Posts
- 1
CWE
- CWE-287
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H