Junglewise Threat Intelligence

CVE-2026-86480: JetBrains Hub authentication bypass in trusted service registration

CVE-2026-86480 · Severity: critical · CVSS 9.8 · Published 2026-09-07

Technologies: Jetbrains Hub. Vendors: Jetbrains.

Executive brief

JetBrains Hub is a server platform used by development teams to manage licenses, user accounts, and integrations across JetBrains tools. An unauthenticated attacker can bypass authentication controls to register a malicious trusted service and gain superuser administrative privileges, giving complete control over the system and all user data.

Technical details

JetBrains Hub contains an authentication bypass vulnerability in its trusted service registration mechanism. An unauthenticated attacker can register a new trusted service without proper authentication checks, leading to superuser privilege escalation. The vulnerability requires no authentication and is remotely exploitable via the network. A successful exploit allows an attacker to gain full administrative control of the Hub instance, including access to all user accounts, licenses, and integrated systems. The vulnerability is fixed in version 2026.2.52442 and later.

Affected products

  • JetBrains Hub before 2026.2.52442

Timeline

  • 2026-09-07: disclosed

References

Related threats