JetBrains Vulnerabilities and Affected Products
Vulnerabilities associated with Hub.
Products
Clear product- TeamCity183 vulnerabilities
- YouTrack62 vulnerabilities
- IntelliJ IDEA49 vulnerabilities
- Hub16 vulnerabilities
- Ktor10 vulnerabilities
- GoLand6 vulnerabilities
- Rider6 vulnerabilities
- Toolbox App6 vulnerabilities
- WebStorm6 vulnerabilities
- PyCharm5 vulnerabilities
- PhpStorm4 vulnerabilities
- Junie3 vulnerabilities
- ReSharper2 vulnerabilities
- RubyMine2 vulnerabilities
- Aqua1 vulnerability
- CLion1 vulnerability
- DataGrip1 vulnerability
- Datalore1 vulnerability
- DataSpell1 vulnerability
- dotTrace1 vulnerability
- ETW Host Service1 vulnerability
- IDE Services1 vulnerability
- intellij_idea1 vulnerability
- JetBrains Gateway1 vulnerability
- Kotlin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-50242CRITICAL | Generated title:JetBrains Hub Authentication Bypass via Direct Database AccessIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible CWE-306Jun 19, 2026 | CVSS10.0v3.1 | EPSS0.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56142CRITICAL | Generated title:JetBrains Hub Improperly Controlled Modification of Dynamically-Determined Object Attributes Leading to Privilege EscalationIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible CWE-915Jun 19, 2026 | CVSS9.6v3.1 | EPSS0.573% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56141CRITICAL | Generated title:JetBrains Hub Account Takeover via Predictable Restore CodesIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible CWE-338Jun 19, 2026 | CVSS9.8v3.1 | EPSS0.522% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32229MEDIUM | Generated title:JetBrains Hub Authentication Bypass via Account MismatchIn JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled CWE-290Mar 11, 2026 | CVSS6.8v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25848CRITICAL | Generated title:JetBrains Hub Authentication BypassIn JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible CWE-306Feb 9, 2026 | CVSS9.1v3.1 | EPSS0.425% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64683MEDIUM | In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API CWE-362Nov 10, 2025 | CVSS5.3v3.1 | EPSS0.204% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit CWE-362Nov 10, 2025 | CVSS2.7v3.1 | EPSS0.157% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations CWE-862Nov 10, 2025 | CVSS2.7v3.1 | EPSS0.188% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-24456MEDIUM | In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping | CVSS6.7v3.1 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-50573MEDIUM | In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services CWE-862Oct 28, 2024 | CVSS4.3v3.1 | EPSS0.221% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible CWE-79Jun 18, 2024 | CVSS3.5v3.1 | EPSS0.238% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-48477MEDIUM | In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing CWE-918Apr 24, 2023 | CVSS4.1v3.1 | EPSS0.482% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-48429MEDIUM | In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible CWE-79Mar 27, 2023 | CVSS4.6v3.1 | EPSS0.603% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address CWE-770Nov 18, 2022 | CVSS3.5v3.1 | EPSS0.518% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services CWE-284Jul 1, 2022 | CVSS3.5v3.1 | EPSS0.564% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-29811MEDIUM | In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible. CWE-79Apr 28, 2022 | CVSS6.1v3.1 | EPSS0.466% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |