An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.)
Use Jupyter vendor hub and Oauthenticator product page to widen CVE-2018-7206 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-33175, CVE-2024-29033 and CVE-2020-26250 for nearby disclosures in the same product family.