Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

View on NVD

Analysis

JetBrains Hub presenta una vulnerabilidad crítica de omisión de autenticación que permite obtener acceso administrativo total al servidor. Al centralizar la identidad de herramientas como TeamCity y YouTrack, este fallo de severidad 10.0 compromete la integridad de la infraestructura de desarrollo y gestión de código. Es urgente actualizar a las versiones corregidas de 2024, 2025 o 2026 para prevenir la toma de control del sistema.

Relevant roles

BackendCyberSecurityJavaLinuxDockerSql

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-306

EPSS

Probability of exploitation (next 30 days): 0.0044 (0.4%)
Percentile: 34.8%
EPSS: 2026-06-23

Technical description

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

Published: 6/19/2026, 1:16:36 PM
Last modified: 6/24/2026, 5:17:29 AM

References

HomeEventsBlogResourcesTeam