CVE-2026-56142
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.62%
- CWE
- CWE-915
- Published
- 2026-06-19
- Last modified
- 2026-06-24
Affected products
- JetBrains Hub
Weakness type
Related vulnerabilities
- CVE-2026-85408 — Eleveo Quality Management Conversation events dynamically-determined object attributes
- CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-83557 — jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types
- CVE-2026-78038 — Job argument injection via :args overrides primary_key and tenant in AshOban
- CVE-2026-77144 — Broken Access Control in extension "Events 2" (events2)
- CVE-2026-71504 — Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset
- CVE-2026-78416 — Authenticated RCE via `condition.config` JSON cleanse bypass
- CVE-2026-62315 — Frappe: Mass assignment via set_value