CVE-2026-25848: JetBrains Hub

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

Affected products

  • JetBrains Hub: before 2025.3.119807 (fixed in 2025.3.119807)

Published 2026-02-09. Last modified 2026-06-17.