
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25848 is an authentication bypass vulnerability in JetBrains Hub that allows unauthenticated attackers to perform administrative actions without valid credentials. It affects all versions of JetBrains Hub before 2025.3.119807. The vulnerability was published on February 9, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 9.8 (Critical) (JetBrains Advisory, Red Hat CVE).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function), meaning certain administrative endpoints or operations in JetBrains Hub fail to enforce authentication checks before execution. An unauthenticated remote attacker can send crafted network requests to these unprotected endpoints to trigger privileged administrative actions. The attack requires no user interaction, no prior privileges, and has low complexity, making it trivially exploitable over the network. No detailed public technical write-up or proof-of-concept code has been identified at this time (JetBrains Advisory, Red Hat CVE).
Successful exploitation grants an unauthenticated attacker full administrative control over the affected JetBrains Hub instance, resulting in high impact to confidentiality, integrity, and availability. Attackers could manipulate user accounts, alter access control configurations, exfiltrate sensitive data (including credentials and tokens stored in Hub), and potentially pivot to connected development tools and repositories integrated with Hub. The complete compromise of a Hub instance could serve as a launchpad for broader supply chain or lateral movement attacks within a development environment (Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is very low at approximately 0.003%, suggesting limited automated exploitation activity currently. However, the critical CVSS score and zero-authentication-required nature of the flaw make it a high-priority target if technical details become public.
JetBrains has released a patch addressing this vulnerability. Administrators should immediately upgrade JetBrains Hub to version 2025.3.119807 or later. No specific configuration-based workaround has been published; upgrading is the only recommended remediation. Organizations should also audit Hub administrative logs for any unexpected configuration changes or unauthorized account activity that may have occurred prior to patching (JetBrains Advisory).
The vulnerability received coverage from security news outlets including The Hacker Wire, which published an article on the authentication bypass and its implications for unauthenticated administrative access (The Hacker Wire). Security aggregators such as Vulners, CVEFeed, and Offseq Radar also indexed the vulnerability shortly after disclosure. Community reaction has been limited, consistent with the absence of a public exploit or confirmed active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."