CVE-2026-50242: Critical severity JetBrains Hub vulnerability
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains Hubto a version that resolves this vulnerability.Fixed in 2026.1.13757 - Upgrade
Upgrade
JetBrains Hubto a version that resolves this vulnerability.Fixed in 2025.3.148033 - Upgrade
Upgrade
JetBrains Hubto a version that resolves this vulnerability.Fixed in 2025.2.148048 - Upgrade
Upgrade
JetBrains Hubto a version that resolves this vulnerability.Fixed in 2025.1.148120 - Upgrade
Upgrade
JetBrains Hubto a version that resolves this vulnerability.Fixed in 2024.3.148430 - Upgrade
Upgrade
JetBrains Hubto a version that resolves this vulnerability.Fixed in 2024.2.148429
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50242?
The severity of CVE-2026-50242 is rated as critical with a score of 10.
What is the risk associated with CVE-2026-50242?
CVE-2026-50242 has a risk rating of 87.
How do I fix CVE-2026-50242?
To fix CVE-2026-50242, upgrade to JetBrains Hub version 2026.1.13757 or later.
What is the main issue with CVE-2026-50242?
CVE-2026-50242 allows authentication bypass via direct database access, potentially leading to unauthorized administrative access.
Which versions of JetBrains Hub are affected by CVE-2026-50242?
CVE-2026-50242 affects JetBrains Hub before versions 2026.1.13757, 2025.3.148033, 2025.2.148048, and several others.