Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-86480: JetBrains Hub lets unauthenticated attacker become admin

CVE-2026-86480 · published 1 month ago
Summary

JetBrains Hub versions released before 2026.2.52442 allow anyone to register a trusted service without logging in. That service gives the attacker full administrative rights over the system. Upgrade Hub to the latest version or apply the vendor’s security update promptly.

What to do
  • Update jetbrains hub to version 2026.2.52442 or later.
Affected software
VendorProductAffected versions
jetbrains hub < 2026.2.52442
Original advisory text
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published7 Sep 2026
Updated11 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-86480 · MITRE
Track software like this
Free during beta