Description
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
Published: 2026-09-07
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker with no authentication credentials can register a trusted service in JetBrains Hub, thereby obtaining superuser privileges. The vulnerability is a direct privilege escalation that grants full control over the Hub instance, allowing the attacker to modify configuration, create users, or execute arbitrary commands. This weakness is classified as CWE-306, enabling an attacker to bypass authentication requirements.

Affected Systems

JetBrains Hub versions prior to 2026.2.52442 are affected. Any deployment of Hub that has not yet applied the 2026.2.52442 update is vulnerable.

Risk and Exploitability

The CVSS score of 9.8 marks this flaw as critical. No EPSS score is available, and it is not listed in CISA's KEV catalog, suggesting a lower public exploitation probability thus far. However, the attack vector is unauthenticated, meaning that the vulnerability can be triggered without any credentials, and it requires no privileged access to the network—any external attacker can exploit it by registering a trusted service.

Generated by OpenCVE AI on September 7, 2026 at 17:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains Hub to version 2026.2.52442 or later.
  • If an immediate upgrade is not feasible, disable unauthenticated trusted service registration or remove the feature until a patch is applied.
  • Monitor system logs for evidence of unauthorized trusted service registrations and enforce strict access controls.

Generated by OpenCVE AI on September 7, 2026 at 17:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Service Registration Grants Superuser Privileges in JetBrains Hub

Mon, 07 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains hub
Vendors & Products Jetbrains
Jetbrains hub

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-09-07T16:26:41.594Z

Reserved: 2026-09-07T16:13:34.032Z

Link: CVE-2026-86480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:26.150

Modified: 2026-09-07T17:17:26.150

Link: CVE-2026-86480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function