Executive brief
JetBrains Hub, a central authentication and authorization service for JetBrains team tools, is vulnerable to a flaw that allows unauthorized users to take over accounts. By predicting the codes used to restore access to an account, an attacker can gain full control over user profiles without needing a password. This could lead to the theft of sensitive developer data, unauthorized access to source code, and disruption of business operations.
Technical details
JetBrains Hub versions prior to the fixed releases (e.g., 2026.1.13757) utilize a cryptographically weak pseudo-random number generator (PRNG) for generating account restoration codes (CWE-338). This weakness makes the restore codes predictable. An unauthenticated remote attacker can exploit this by initiating a password reset or account recovery process and guessing the valid code. Successful exploitation results in full account takeover, granting the attacker the same privileges as the victim user. The vulnerability is rated critical due to the lack of required authentication or user interaction.
Affected products
- JetBrains Hub Before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
Timeline
- 2026-06-19: advisory: Initial disclosure by JetBrains and NVD publication
- 2026-06-19: patched: Fixes released in multiple version branches including 2026.1.13757