CVE-2026-25848: Critical severity JetBrains Hub vulnerability
Published Feb 9, 2026
·Updated
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Affected Software
2 affected components
JetBrains Hub<2025.3.119807
JetBrains Hub<2025.3.119807
Event History
Feb 9, 2026
CVE Published
via MITRE·10:39 AM
Data Sourced
via MITRE·10:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Nov 23, 58106
Event
via FIRST·11:19 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-25848?
CVE-2026-25848 is classified as a critical vulnerability due to its ability to allow unauthorized administrative access.
2
How do I fix CVE-2026-25848?
To mitigate CVE-2026-25848, upgrade JetBrains Hub to version 2025.3.119808 or later immediately.
3
What actions can be performed due to CVE-2026-25848?
Due to CVE-2026-25848, attackers can perform administrative actions without proper authentication.
4
Which versions of JetBrains Hub are affected by CVE-2026-25848?
CVE-2026-25848 affects all versions of JetBrains Hub before 2025.3.119807.
5
Is there a workaround for CVE-2026-25848 while I update?
There are no known workarounds for CVE-2026-25848, so updating to the fixed version is recommended.