Back to overview

CVE-2026-50242

CRITICAL
10.0
CVSS 3.1
Description
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

Metadata

CVE ID
CVE-2026-50242
State
PUBLISHED
Assigner
JetBrains
Reserved
2026-06-04 13:03 UTC
Published
2026-06-19 11:49 UTC
Last updated
2026-06-19 11:49 UTC
Primary CWE
CWE-306
CWE-306
Vendor / Product
JetBrains / Hub
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
JetBrains Hub 0 < 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview