CVE-2026-50242
Received
Received - Intake
Authentication Bypass in JetBrains Hub via Database Access
Publication date: 2026-06-19
Last updated on: 2026-06-19
Assigner: JetBrains s.r.o.
Description
Description
In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jetbrains | hub | to 2026.1.13757 (exc) |
| jetbrains | hub | to 2025.3.148033 (exc) |
| jetbrains | hub | to 2025.2.148048 (exc) |
| jetbrains | hub | to 2025.1.148120 (exc) |
| jetbrains | hub | to 2024.3.148430 (exc) |
| jetbrains | hub | to 2024.2.148429 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |