CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-25848

CVSS 9.1v3.1pub. 2026-02-09upd. 2026-02-18

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function), which means that certain administrative functions or endpoints in JetBrains Hub did not require proper authentication before execution. A remote attacker, without providing login credentials, could invoke critical operations reserved for administrators. The network attack vector (AV:N), no complexity requirements (AC:L), no privilege requirements (PR:N), and no user interaction requirements (UI:N) make this vulnerability particularly dangerous.

Impact

An unauthenticated attacker can perform privileged administrative actions, leading to high risk of breach of confidentiality and integrity of data managed by JetBrains Hub, including potential takeover of user and permission management.

Mitigation & patch

JetBrains Hub should be updated immediately to version 2025.3.119807 or later. Details are available on the vendor's website: https://www.jetbrains.com/privacy-security/issues-fixed/

Who is affected

JetBrains Hub in all versions prior to 2025.3.119807

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Jetbrains Hub

    APP
    Jetbrains
    < 2025.3.119807
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-56142CRITICAL9.9PL ✓same product

JetBrains Hub — privilege escalation przez dołączanie danych uwierzytelniających do kont

CVE-2026-50242CRITICAL10.0PL ✓same product

JetBrains Hub — pominięcie uwierzytelnienia przez bezpośredni dostęp do bazy danych

CVE-2026-56141CRITICAL9.8PL ✓same product

JetBrains Hub — przejęcie konta przez przewidywalne kody przywracania

CVE-2022-25260CRITICAL9.1PL ✓same product

Blind SSRF w JetBrains Hub — nieautoryzowany dostęp do zasobów wewnętrznych

CVE-2022-25262CRITICAL9.8PL ✓same product

Przejęcie żądania SAML w JetBrains Hub (przed wersją 2022.1.14434)