Executive brief
JetBrains Hub is a server platform used by development teams to manage licenses, user accounts, and integrations across JetBrains tools. An unauthenticated attacker can bypass authentication controls to register a malicious trusted service and gain superuser administrative privileges, giving complete control over the system and all user data.
Technical details
JetBrains Hub contains an authentication bypass vulnerability in its trusted service registration mechanism. An unauthenticated attacker can register a new trusted service without proper authentication checks, leading to superuser privilege escalation. The vulnerability requires no authentication and is remotely exploitable via the network. A successful exploit allows an attacker to gain full administrative control of the Hub instance, including access to all user accounts, licenses, and integrated systems. The vulnerability is fixed in version 2026.2.52442 and later.
Affected products
- JetBrains Hub before 2026.2.52442
Timeline
- 2026-09-07: disclosed