Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2026-44180

CVE-2026-44180 is a critical input validation flaw in Jupyter Enterprise Gateway versions 2.0.0rc1 through 3.2.x that allows attackers to bypass the default prohibition on running kernels as root (UID/GID 0). By supplying a specially crafted KERNEL_UID or KERNEL_GID value, an attacker can launch Jupyter kernels with root privileges, potentially leading to container escapes, compromise of worker nodes, and full cluster takeover. The issue is resolved in version 3.0.0.

publishedJul 17, 2026
last modifiedJul 17, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
38th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Jupyter Enterprise Gateway

02

Real-world impact

Attackers can gain root access inside containers, escape to the host, and compromise the entire Kubernetes cluster.

03

Why this severity

CVSS 9.8 (Critical) due to network‑adjacent, low‑complexity attack requiring no privileges or user interaction, with high impact on confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade Jupyter Enterprise Gateway to version 3.0.0 or later.

Fix information comes from the NVD description which states the issue has been fixed in version 3.0.0.

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-44180: CVE-2026-44180 is a critical input validation flaw in Jupyter Enterpri · Vulnary