What is CVE-2026-73627?
CVE-2026-73627 is a plugin manager lock-rule enforcement bypass vulnerability in JupyterLab. Affected versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 allow authenticated users to circumvent administrator lock rules via server-side enforcement gaps at the /lab/api/plugins endpoint. Users should immediately update to the latest patched version and restrict access to the affected endpoint.
Azərbaycanca: CVE-2026-73627 JupyterLab-da plagin meneceri kilid qaydalarının bypass zəifliyidir. >=4.1.0,<=4.5.9 və >=4.6.0,<=4.6.1 versiyalarında autentifikasiyalı istifadəçi server tərəfindəki boşluqlar vasitəsilə administrator kilidlərini keçə bilir. İstifadəçilər təcili olaraq ən son versiyaya yenilənməli və `/lab/api/plugins` endpoint-ə girişi məhdudlaşdırmalıdırlar.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which JupyterLab versions are affected by CVE-2026-73627?
Versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 are affected by this vulnerability.
What measures should be taken to mitigate CVE-2026-73627?
Users should immediately update to the latest patched version and restrict access to the `/lab/api/plugins` endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.