CVE-2026-86480: JetBrains Hub

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

Affected products

  • JetBrains Hub: before 2026.2.52442 (fixed in 2026.2.52442)

Published 2026-09-07. Last modified 2026-09-09.