CVE-2026-86480

9.8

JetBrains · Hub

JetBrains Hub contains a flaw allowing unauthenticated attackers to register a trusted service, resulting in the acquisition of superuser privileges.

Executive summary

An unauthenticated remote code execution vulnerability in JetBrains Hub allows attackers to gain full administrative control over the application.

Vulnerability

This vulnerability is a missing authentication for critical function (CWE-306) where an unauthenticated attacker can register a trusted service. By leveraging this flaw, the attacker gains superuser privileges within the affected Hub instance.

Business impact

The ability for an unauthenticated user to elevate privileges to superuser status represents a complete compromise of the JetBrains Hub platform. Given the CVSS score of 9.8, this vulnerability poses a critical risk to data confidentiality, integrity, and availability, potentially allowing attackers to access sensitive project data, modify configurations, or perform administrative tasks across the organization.

Remediation

Immediate Action: Update JetBrains Hub to version 2026.2.52442 or later to address the authentication bypass.

Proactive Monitoring: Review audit logs for unusual service registration events or unauthorized modifications to administrative user accounts.

Compensating Controls: Ensure that the Hub instance is not directly exposed to the public internet and restrict access to authorized management networks via VPN or IP allowlisting.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability is critical due to the potential for total system takeover by an unauthenticated attacker. Administrators must prioritize the deployment of the vendor provided update to version 2026.2.52442 immediately. Failure to patch allows for trivial escalation of privileges, which could lead to widespread unauthorized access within the development environment.

More JetBrains CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources