
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100266 is a missing authorization vulnerability in JetBrains Hub that allows authenticated users to send arbitrary emails from the server's trusted address. It affects all versions of JetBrains Hub before 2026.2.52366. The vulnerability was published on September 30, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 7.7 (High) (Feedly, JetBrains).
The root cause is CWE-862 (Missing Authorization) — the application fails to enforce proper access controls on the email-sending functionality, allowing any authenticated user to trigger outbound emails from the server's trusted mail address (Feedly). The attack vector is network-based, requires low privileges (a valid authenticated session), and no user interaction, with a changed scope indicating impact beyond the vulnerable component itself. No public proof-of-concept code or detailed technical write-ups have been identified at this time.
Successful exploitation allows an authenticated attacker to send arbitrary emails appearing to originate from the JetBrains Hub server's trusted address, which could be leveraged for phishing campaigns, social engineering, or bypassing email-based trust controls targeting other users or external parties. The integrity impact is rated High due to the potential for abuse of the server's trusted sender identity, while confidentiality and availability are not directly affected (Feedly, JetBrains).
No public proof-of-concept exploits or evidence of in-the-wild exploitation have been reported as of the disclosure date (Feedly). The NVD SSVC assessment indicates exploitation is currently "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting a low probability of near-term exploitation. Exploitation does require a valid authenticated account on the Hub instance, which limits the attack surface compared to unauthenticated vulnerabilities.
JetBrains has released a fix in JetBrains Hub version 2026.2.52366. Organizations should upgrade to this version or later as the primary remediation (JetBrains). No specific configuration-based workarounds have been published; as an interim measure, administrators should restrict Hub access to trusted users only and monitor outbound email activity for anomalies until patching is complete.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."