
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50242 is a critical authentication bypass vulnerability in JetBrains Hub that allows unauthenticated attackers to gain administrative access via direct database access. It affects JetBrains Hub versions before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. The vulnerability was published on June 19, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, and 10.0 (Critical) per ENISA/GitHub Advisory with a scope-changed vector (GitHub Advisory, JetBrains).
The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function), meaning the application fails to enforce authentication controls for a critical database-accessible function that can confer administrative privileges. An attacker with network access to the Hub database can interact with it directly — bypassing the application's authentication layer entirely — and leverage that access to escalate to full administrative control of the Hub instance. No privileges or user interaction are required, and the attack complexity is low, making it highly automatable (GitHub Advisory, JetBrains).
Successful exploitation grants an unauthenticated attacker full administrative access to JetBrains Hub, a centralized team and user management platform. This enables complete confidentiality loss (access to all user data, credentials, and configurations), integrity loss (modification of any user account, group membership, or system settings), and availability impact (potential service disruption). Because Hub typically serves as an identity and access management hub for other JetBrains tools (e.g., YouTrack, TeamCity), compromise could facilitate lateral movement across the broader JetBrains toolchain (GitHub Advisory, JetBrains).
JetBrains has released patched versions addressing this vulnerability: 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. Organizations should upgrade to the appropriate patched version immediately. As a workaround, restrict network access to the Hub database so it is not directly reachable from untrusted networks, and implement network segmentation and firewall rules to limit database exposure to only the Hub application server (JetBrains, GitHub Advisory).
JetBrains published a security update blog post alongside the fix, noting the issue in their YouTrack security update announcement (JetBrains Blog). Community discussion was observed on Mastodon and Bluesky shortly after disclosure, and the vulnerability was picked up by threat intelligence aggregators including Tenable (Nessus plugin 322257) and VulnDB. No major independent security researcher write-ups or significant media coverage beyond standard CVE tracking were identified at the time of this report.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."