Junglewise Threat Intelligence

CVE-2026-56141: JetBrains Hub account takeover via predictable restore codes

CVE-2026-56141 · Severity: critical · CVSS 9.8 · Published 2026-06-19

Technologies: Jetbrains Hub. Vendors: Jetbrains.

Executive brief

JetBrains Hub, a central authentication and authorization service for JetBrains team tools, is vulnerable to a flaw that allows unauthorized users to take over accounts. By predicting the codes used to restore access to an account, an attacker can gain full control over user profiles without needing a password. This could lead to the theft of sensitive developer data, unauthorized access to source code, and disruption of business operations.

Technical details

JetBrains Hub versions prior to the fixed releases (e.g., 2026.1.13757) utilize a cryptographically weak pseudo-random number generator (PRNG) for generating account restoration codes (CWE-338). This weakness makes the restore codes predictable. An unauthenticated remote attacker can exploit this by initiating a password reset or account recovery process and guessing the valid code. Successful exploitation results in full account takeover, granting the attacker the same privileges as the victim user. The vulnerability is rated critical due to the lack of required authentication or user interaction.

Affected products

  • JetBrains Hub Before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429

Timeline

  • 2026-06-19: advisory: Initial disclosure by JetBrains and NVD publication
  • 2026-06-19: patched: Fixes released in multiple version branches including 2026.1.13757

References

Related threats