ZeroHour

CVE-2026-86480

moderate

Unauthenticated superuser privilege escalation in JetBrains Hub

CVSS 3.1
9.8 critical
EPSS
<1%p22
Published
()
Modified
AI analysis

JetBrains Hub before 2026.2.52442 fails to require authentication (CWE-306) for its trusted-service registration function. An unauthenticated attacker with network access to a Hub instance can call the service-registration endpoint, register themselves as a trusted service, and thereby obtain superuser privileges over the Hub server. Because Hub serves as the identity and account-management server for JetBrains on-premises team tools, superuser access can let the attacker control user accounts, permissions, and settings in the Hub environment. Any deployment running a Hub version earlier than 2026.2.52442 is affected, with internet-exposed instances at greatest risk. There are no known public exploits, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Upgrade JetBrains Hub to version 2026.2.52442 or later. Until patched, restrict network access to the Hub service (firewall/allowlist) and, if Hub was internet-exposed, audit for unknown registered trusted services and unexpected superuser activity. Review authentication logs and rotate credentials for Hub-managed accounts if compromise is suspected.

Affected
JetBrains Huball versions before 2026.2.52442
Estimated exposure
moderatelikely on the order of thousands of internet-exposed Hub instances out of a smaller overall install base — Hub is a niche identity server bundled with or deployed alongside JetBrains on-premises team tools, typically placed behind corporate firewalls, so the exposed subset is plausibly in the low thousands rather than six or seven figures.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.