
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-100266 is a missing authorization vulnerability in JetBrains Hub that allows authenticated users to send arbitrary emails from the server's trusted address. It affects all versions of JetBrains Hub before 2026.2.52366. The vulnerability was published on September 30, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 7.7 (High) (Feedly, JetBrains).
The root cause is CWE-862 (Missing Authorization) — the application fails to enforce proper access controls on the email-sending functionality, allowing any authenticated user to trigger outbound emails from the server's trusted mail address (Feedly). The attack vector is network-based, requires low privileges (a valid authenticated session), and no user interaction, with a changed scope indicating impact beyond the vulnerable component itself. No public proof-of-concept code or detailed technical write-ups have been identified at this time.
Successful exploitation allows an authenticated attacker to send arbitrary emails appearing to originate from the JetBrains Hub server's trusted address, which could be leveraged for phishing campaigns, social engineering, or bypassing email-based trust controls targeting other users or external parties. The integrity impact is rated High due to the potential for abuse of the server's trusted sender identity, while confidentiality and availability are not directly affected (Feedly, JetBrains).
No public proof-of-concept exploits or evidence of in-the-wild exploitation have been reported as of the disclosure date (Feedly). The NVD SSVC assessment indicates exploitation is currently "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting a low probability of near-term exploitation. Exploitation does require a valid authenticated account on the Hub instance, which limits the attack surface compared to unauthenticated vulnerabilities.
JetBrains has released a fix in JetBrains Hub version 2026.2.52366. Organizations should upgrade to this version or later as the primary remediation (JetBrains). No specific configuration-based workarounds have been published; as an interim measure, administrators should restrict Hub access to trusted users only and monitor outbound email activity for anomalies until patching is complete.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."