Vulnerability DatabaseCVE-2026-100266

CVE-2026-100266: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-100266 is a missing authorization vulnerability in JetBrains Hub that allows authenticated users to send arbitrary emails from the server's trusted address. It affects all versions of JetBrains Hub before 2026.2.52366. The vulnerability was published on September 30, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 7.7 (High) (Feedly, JetBrains).

Technical details

The root cause is CWE-862 (Missing Authorization) — the application fails to enforce proper access controls on the email-sending functionality, allowing any authenticated user to trigger outbound emails from the server's trusted mail address (Feedly). The attack vector is network-based, requires low privileges (a valid authenticated session), and no user interaction, with a changed scope indicating impact beyond the vulnerable component itself. No public proof-of-concept code or detailed technical write-ups have been identified at this time.

Impact

Successful exploitation allows an authenticated attacker to send arbitrary emails appearing to originate from the JetBrains Hub server's trusted address, which could be leveraged for phishing campaigns, social engineering, or bypassing email-based trust controls targeting other users or external parties. The integrity impact is rated High due to the potential for abuse of the server's trusted sender identity, while confidentiality and availability are not directly affected (Feedly, JetBrains).

Exploitability

No public proof-of-concept exploits or evidence of in-the-wild exploitation have been reported as of the disclosure date (Feedly). The NVD SSVC assessment indicates exploitation is currently "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting a low probability of near-term exploitation. Exploitation does require a valid authenticated account on the Hub instance, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Obtain authenticated access: Log in to a JetBrains Hub instance running a version prior to 2026.2.52366 using any valid user account.
  2. Identify the email-sending endpoint: Locate the Hub API or UI functionality responsible for sending emails (e.g., notification or invitation features) that lacks proper authorization enforcement.
  3. Craft a malicious email request: Construct an HTTP request to the vulnerable endpoint with arbitrary recipient addresses and custom email content, bypassing the expected authorization checks.
  4. Send the email: Submit the request; the Hub server dispatches the email from its trusted server address, making it appear legitimate to recipients and potentially bypassing spam filters or email authentication controls (e.g., SPF/DKIM).
  5. Leverage for phishing or social engineering: Use the trusted sender identity to deceive recipients into clicking malicious links, disclosing credentials, or taking other harmful actions.

Indicators of compromise

  • Logs: Hub application logs showing email dispatch events initiated by low-privilege user accounts, particularly to external or unexpected recipient addresses; anomalous volume of outbound email events from a single authenticated session.
  • Network: Unusual outbound SMTP traffic from the Hub server to external mail servers not consistent with normal notification patterns.
  • Application: Hub audit logs recording email-related API calls from accounts that would not normally trigger bulk or arbitrary email sending.

Mitigation and workarounds

JetBrains has released a fix in JetBrains Hub version 2026.2.52366. Organizations should upgrade to this version or later as the primary remediation (JetBrains). No specific configuration-based workarounds have been published; as an interim measure, administrators should restrict Hub access to trusted users only and monitor outbound email activity for anomalies until patching is complete.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103493HIGH8.1
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103494MEDIUM6.6
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103495MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management