CVE-2026-86480
moderateUnauthenticated superuser privilege escalation in JetBrains Hub
JetBrains Hub before 2026.2.52442 fails to require authentication (CWE-306) for its trusted-service registration function. An unauthenticated attacker with network access to a Hub instance can call the service-registration endpoint, register themselves as a trusted service, and thereby obtain superuser privileges over the Hub server. Because Hub serves as the identity and account-management server for JetBrains on-premises team tools, superuser access can let the attacker control user accounts, permissions, and settings in the Hub environment. Any deployment running a Hub version earlier than 2026.2.52442 is affected, with internet-exposed instances at greatest risk. There are no known public exploits, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Upgrade JetBrains Hub to version 2026.2.52442 or later. Until patched, restrict network access to the Hub service (firewall/allowlist) and, if Hub was internet-exposed, audit for unknown registered trusted services and unexpected superuser activity. Review authentication logs and rotate credentials for Hub-managed accounts if compromise is suspected.
| JetBrains Hub | all versions before 2026.2.52442 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.