Junglewise Threat Intelligence

CVE-2026-56142: JetBrains Hub privilege escalation via authentication detail attachment

CVE-2026-56142 · Severity: critical · CVSS 9.9 · Published 2026-06-19

Technologies: Jetbrains Hub. Vendors: Jetbrains.

Executive brief

JetBrains Hub, a central authentication and authorization service for JetBrains team tools, contains a vulnerability that allows users to escalate their privileges. By improperly attaching authentication details to accounts, an attacker could gain unauthorized access to administrative functions or other users' data. This could lead to a full compromise of the identity management system and the integrated tools it supports.

Technical details

A privilege escalation vulnerability exists in JetBrains Hub due to improper control of dynamically-determined object attributes (CWE-915). An authenticated attacker with low-level permissions can exploit this by attaching specific authentication details to accounts, effectively bypassing intended access controls. The vulnerability is reachable over the network and has a high impact on confidentiality, integrity, and availability across the security scope. JetBrains has released several patched versions across different release branches to address this issue.

Affected products

  • JetBrains Hub Before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory

References

Related threats