Junglewise Threat Intelligence

CVE-2026-50242: JetBrains Hub authentication bypass leading to administrative access

CVE-2026-50242 · Severity: critical · CVSS 10 · Published 2026-06-19

Technologies: Jetbrains Hub. Vendors: Jetbrains.

Executive brief

JetBrains Hub, a central authentication and authorization service for JetBrains team tools, contains a critical vulnerability that allows unauthorized users to bypass security checks. By exploiting this flaw, an attacker can gain full administrative control over the system without needing a password. This could lead to the total compromise of user accounts, sensitive project data, and the integrity of the development environment.

Technical details

An authentication bypass vulnerability exists in JetBrains Hub due to missing authentication for critical functions (CWE-306). The flaw allows an unauthenticated remote attacker to gain administrative access by leveraging direct database access mechanisms. With a CVSS score of 10.0, the vulnerability is highly exploitable over the network with no user interaction required. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability. The issue is fixed in versions 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429.

Affected products

  • JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory

References

Related threats