CVE-2026-56142
Received Received - Intake
Privilege Escalation in JetBrains Hub

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: JetBrains s.r.o.

Description
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-21
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
jetbrains hub to 2026.1.13757 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in JetBrains Hub versions before 2026.1.13757 and certain earlier versions. It allows privilege escalation by attaching authentication details to accounts, which means an attacker with some level of access could increase their privileges improperly.

Impact Analysis

The vulnerability can have a severe impact because it allows an attacker to escalate privileges, potentially gaining higher-level access than intended. This can lead to full compromise of the affected system, including complete control over confidentiality, integrity, and availability of data and services.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56142. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart