CVE-2026-86480: Critical severity JetBrains Hub vulnerability
Published Sep 7, 2026
·Updated
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
Affected Software
1 affected component
JetBrains Hub<2026.2.52442
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The issue can be exploited by an unauthenticated attacker. The attacker could register a trusted service and use that to gain superuser privileges.
2
Which deployments are affected?
JetBrains Hub versions before 2026.2.52442 are affected. The provided information does not identify any configuration prerequisite, so deployments running an earlier version should be treated as exposed.
3
What is the remediation?
Update JetBrains Hub to version 2026.2.52442 or later. The provided information does not describe a temporary mitigation if updating cannot be performed immediately.