CVE-2026-100266
- EPSS 0.23%
- Veröffentlicht 30.09.2026 15:17:50
- Zuletzt bearbeitet 02.10.2026 16:47:10
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
CVE-2026-86480
- EPSS 0.29%
- Veröffentlicht 07.09.2026 17:17:26
- Zuletzt bearbeitet 09.09.2026 05:18:19
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
CVE-2026-50242
- EPSS 0.6%
- Veröffentlicht 19.06.2026 11:49:42
- Zuletzt bearbeitet 26.06.2026 13:20:46
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
CVE-2026-56142
- EPSS 0.57%
- Veröffentlicht 19.06.2026 11:49:41
- Zuletzt bearbeitet 26.06.2026 13:06:12
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
CVE-2026-56141
- EPSS 0.52%
- Veröffentlicht 19.06.2026 11:49:41
- Zuletzt bearbeitet 26.06.2026 13:10:35
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
CVE-2026-32229
- EPSS 0.17%
- Veröffentlicht 11.03.2026 15:03:37
- Zuletzt bearbeitet 02.04.2026 13:11:36
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
CVE-2026-25848
- EPSS 0.43%
- Veröffentlicht 09.02.2026 10:39:02
- Zuletzt bearbeitet 18.02.2026 17:56:13
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
CVE-2025-64683
- EPSS 0.2%
- Veröffentlicht 10.11.2025 13:27:56
- Zuletzt bearbeitet 21.11.2025 16:09:48
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
CVE-2025-64682
- EPSS 0.16%
- Veröffentlicht 10.11.2025 13:27:55
- Zuletzt bearbeitet 20.11.2025 19:53:25
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
CVE-2025-64681
- EPSS 0.19%
- Veröffentlicht 10.11.2025 13:27:54
- Zuletzt bearbeitet 20.11.2025 19:54:04
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations