Impact
An attacker with no authentication credentials can register a trusted service in JetBrains Hub, thereby obtaining superuser privileges. The vulnerability is a direct privilege escalation that grants full control over the Hub instance, allowing the attacker to modify configuration, create users, or execute arbitrary commands. This weakness is classified as CWE-306, enabling an attacker to bypass authentication requirements.
Affected Systems
JetBrains Hub versions prior to 2026.2.52442 are affected. Any deployment of Hub that has not yet applied the 2026.2.52442 update is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical. No EPSS score is available, and it is not listed in CISA's KEV catalog, suggesting a lower public exploitation probability thus far. However, the attack vector is unauthenticated, meaning that the vulnerability can be triggered without any credentials, and it requires no privileged access to the network—any external attacker can exploit it by registering a trusted service.
OpenCVE Enrichment