CVE-2026-56141 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-56141 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-56141 is an account takeover vulnerability in JetBrains Hub, the centralized user management and authentication hub used across JetBrains developer tooling, caused by predictable account restore codes.
Technical Detail
The flaw exists in the account recovery mechanism of JetBrains Hub, where restore codes generated for account recovery are sufficiently predictable that an attacker can enumerate or calculate valid codes without prior access to the target account. By obtaining or guessing a valid restore code, an attacker can complete the account recovery flow and gain full control of an arbitrary user account, including administrative accounts. The impact is complete account takeover with no authentication required, earning this vulnerability a CVSS score of 9.8 Critical.
Exploitation Status
No known exploit code has been publicly disclosed and this vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The exploit maturity is assessed as no known exploit at this time, though the predictable nature of the flaw means a functional exploit could be developed with relatively low effort once the vulnerability mechanics are understood.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor involvement has been identified in connection with this vulnerability.
What To Do
Organizations running JetBrains Hub should patch immediately given the critical severity and the account takeover impact. Fixed versions are Hub 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. Administrators should apply the appropriate patch for their release branch without delay. As an interim measure, consider restricting access to the Hub instance to trusted network segments or VPN, and auditing recent account recovery activity for signs of unauthorized use. Monitoring for unusual account recovery requests or logins following recovery events is advisable until patching is complete.