CVE-2026-56142 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-56142 | CVSS 9.9 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-56142 is a privilege escalation vulnerability in JetBrains Hub, the centralized user management and authentication hub used across JetBrains team tools, affecting multiple release branches prior to patched builds released in 2024 through 2026.
Technical Detail
The flaw allows an attacker to escalate privileges by attaching arbitrary authentication details to existing accounts within JetBrains Hub. The precise mechanism involves improper authorization controls around the account authentication attachment workflow, enabling a lower-privileged or unauthenticated actor to associate credentials with accounts they do not own or control. Successful exploitation could result in full account takeover or administrative privilege escalation within the Hub instance, with downstream impact on any JetBrains products integrated with the affected Hub deployment.
Exploitation Status
No known exploit exists for this vulnerability at this time. The exploit maturity is currently unconfirmed, with no public proof-of-concept code or active exploitation reported. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog as of June 26, 2026.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this vulnerability in available intelligence sources.
What To Do
Organizations running JetBrains Hub should apply the relevant patched build immediately given the critical CVSS score of 9.9. The fixed versions are: 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. Administrators should verify their installed Hub version against these baselines and prioritize upgrade for any internet-facing or internally accessible Hub instances. Until patching is complete, consider restricting access to the Hub administrative interface to trusted network segments and auditing account authentication configurations for unauthorized modifications. Monitor Hub access logs for anomalous account linkage or authentication attachment events as a detection signal.