CVE-2026-40934
CVE-2026-40934 is a medium-severity vulnerability in Jupyter Jupyter Server with a CVSS 3.x base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-613.
Key facts
- Severity: Medium (CVSS 3.x base score 6.8)
- CVSS v4: 7.6
- EPSS exploit prediction: 0% (30th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-27513
- Weakness: CWE-613
- Affected product: Jupyter Jupyter Server
- Published:
- Last modified:
Description
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0.
Frequently asked questions
- What is CVE-2026-40934?
- Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0.
- How severe is CVE-2026-40934?
- CVE-2026-40934 has a CVSS 3.x base score of 6.8, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-40934 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-40934?
- CVE-2026-40934 affects Jupyter Jupyter Server. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-40934?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-40934 have an EU (EUVD) identifier?
- Yes. CVE-2026-40934 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-27513.
- When was CVE-2026-40934 published?
- CVE-2026-40934 was published on 2026-05-05 and last updated on 2026-07-25.
References
Affected products (1)
- cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*
More vulnerabilities in Jupyter Jupyter Server
- CVE-2026-6657 — High (CVSS 8.8): A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation…
- CVE-2026-35397 — High (CVSS 8.8): Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal…
- CVE-2026-5422 — High (CVSS 8.1): A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary…
- CVE-2024-35178 — High (CVSS 7.5): The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability…
- CVE-2022-24757 — High (CVSS 7.5): The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web…
- CVE-2026-40110 — High (CVSS 7.3): Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header…
All CVEs affecting Jupyter Jupyter Server →
Other CWE-613 (Insufficient Session Expiration) vulnerabilities
- CVE-2024-8888 — Critical (CVSS 10.0): An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the…
- CVE-2026-79313 — Critical (CVSS 9.8): webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on…
- CVE-2026-82311 — Critical (CVSS 9.8): Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions,…
- CVE-2026-84480 — Critical (CVSS 9.8): WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to…
- CVE-2026-14950 — Critical (CVSS 9.8): An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session…
- CVE-2026-46455 — Critical (CVSS 9.8): Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper…
Browse all CWE-613 (Insufficient Session Expiration) vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 117.50.215.132 (ipv4-addr)
- 23.239.4.194 (ipv4-addr)
- 129.212.181.245 (ipv4-addr)
- 163.180.4.225 (ipv4-addr)
- 31.22.104.202 (ipv4-addr)
- 150.158.75.120 (ipv4-addr)
- 115.31.175.189 (ipv4-addr)
- 40.192.121.249 (ipv4-addr)