CVE-2026-50242 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-50242 | CVSS 10.0 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-50242 is a critical authentication bypass vulnerability in JetBrains Hub, a centralized user management and authentication platform, that allows an attacker to gain administrative access through direct database manipulation.
Technical Detail
The flaw permits an unauthenticated or low-privileged attacker to bypass Hub's authentication mechanisms by interacting directly with the underlying database, circumventing normal credential validation and session controls. Successful exploitation results in full administrative access to the Hub instance, which controls user accounts, permissions, and authentication tokens for integrated JetBrains products such as YouTrack, TeamCity, and Upsource. The attack surface is significant given Hub's role as a central identity provider; compromise of Hub can cascade into unauthorized access across all connected services and repositories.
Exploitation Status
No known exploit code has been publicly observed or confirmed as of June 26, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. While no active exploitation has been reported, the CVSS score of 10.0 and the nature of the flaw make it a high-priority target for threat actors once awareness increases.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE in available intelligence sources.
What To Do
Organizations running JetBrains Hub should patch immediately to one of the following fixed versions: 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, or 2024.2.148429, depending on the release branch in use. Given the CVSS 10.0 rating and the administrative access impact, this should be treated as an emergency patch with no deferral. As an interim measure, restrict network access to the Hub administrative interface and database ports to trusted internal hosts only, and audit Hub administrator accounts for any unauthorized additions or permission changes. Organizations should also review authentication logs for anomalous direct database connection attempts or unexpected administrative session creation. Downstream JetBrains services integrated with Hub should be reviewed for signs of unauthorized access following any Hub compromise.