📦

hub

Vendor: jetbrains

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 1 Remote Access
Total CVEs 43 Total Indexed
Avg. EPSS 0.68% Exploit Prob.
Latest CVE CVE-2026-56142 Jun 19

Security Vulnerability Index

Page 1 / 5
9.9 CVSS

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible

EPSS: 0.42%
9.8 CVSS

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible

EPSS: 0.37%
10.0 CVSS

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

EPSS: 0.42%
6.8 CVSS

In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

EPSS: 0.17%
9.1 CVSS

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

EPSS: 0.43%
5.3 CVSS

In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

EPSS: 0.20%
2.7 CVSS

In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

EPSS: 0.15%
2.7 CVSS

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

EPSS: 0.18%
6.7 CVSS

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

EPSS: 0.28%
4.3 CVSS

In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

EPSS: 0.22%