CVE-2026-100266: High severity JetBrains Hub vulnerability
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated JetBrains Hub user can exploit it. The attacker needs valid access to Hub, but no user interaction is required.
What is the impact of successful exploitation?
An attacker can send arbitrary emails using the server's trusted email address. This can enable impersonation of legitimate server-originated communications.
Which deployments are affected?
JetBrains Hub versions before 2026.2.52366 are affected. The provided information does not identify configuration-specific conditions or exclusions.
What should teams do if they cannot update immediately?
The provided information does not specify a workaround or mitigation. Prioritize restricting authenticated access to trusted users and update to 2026.2.52366 or later when possible.