CVE-2026-56141: JetBrains Hub
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
Affected products
- JetBrains Hub: from 2024.2.33606, before 2024.2.148429 (fixed in 2024.2.148429); from 2024.3.44799, before 2024.3.148430 (fixed in 2024.3.148430); from 2025.1.62455, before 2025.1.148120 (fixed in 2025.1.148120); from 2025.2.86069, before 2025.2.148048 (fixed in 2025.2.148048); from 2025.3.104432, before 2025.3.148033 (fixed in 2025.3.148033); from 2026.1.12024, before 2026.1.13757 (fixed in 2026.1.13757)
Published 2026-06-19. Last modified 2026-06-26.