VendorsJetBrainshubany version
Vulnerabilities

JetBrains Hub any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2026-50242
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Published 2026-06-19 · Analyzed
10.0EPSS 0.006
CVE-2026-56142
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
Published 2026-06-19 · Analyzed
9.9EPSS 0.006
CVE-2022-25262
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
Published 2022-02-25 · Modified
9.8EPSS 0.014
CVE-2021-43183
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
Published 2021-11-09 · Modified
9.8EPSS 0.012
CVE-2021-36209
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
Published 2021-08-06 · Modified
9.8EPSS 0.010
CVE-2026-25848
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Published 2026-02-09 · Analyzed
9.8EPSS 0.006
CVE-2026-56141
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
Published 2026-06-19 · Analyzed
9.8EPSS 0.005
CVE-2022-48477
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
Published 2023-04-24 · Modified
9.8EPSS 0.005
CVE-2022-25260
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
Published 2022-02-25 · Modified
9.1EPSS 0.024
CVE-2025-24456
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
Published 2025-01-21 · Analyzed
8.8EPSS 0.003
CVE-2021-43180
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
Published 2021-11-09 · Modified
7.5EPSS 0.010
CVE-2021-43182
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
Published 2021-11-09 · Modified
7.5EPSS 0.010
CVE-2022-24327
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
Published 2022-02-25 · Modified
7.5EPSS 0.009
CVE-2020-11691
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
Published 2020-04-22 · Modified
7.5EPSS 0.009
CVE-2021-31901
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
Published 2021-05-11 · Modified
7.5EPSS 0.009
CVE-2022-45471
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
Published 2022-11-18 · Modified
7.5EPSS 0.006
CVE-2025-64683
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
Published 2025-11-10 · Analyzed
7.5EPSS 0.002
CVE-2019-12847
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.
Published 2019-07-03 · Modified
7.2EPSS 0.011
CVE-2026-32229
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
Published 2026-03-11 · Analyzed
6.8EPSS 0.003
CVE-2022-24328
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
Published 2022-02-25 · Modified
6.5EPSS 0.008
CVE-2021-25759
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.
Published 2021-02-03 · Modified
6.5EPSS 0.007
CVE-2021-37540
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
Published 2021-08-06 · Modified
6.5EPSS 0.007
CVE-2021-25757
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
Published 2021-02-03 · Modified
6.1EPSS 0.006
CVE-2021-43181
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
Published 2021-11-09 · Modified
6.1EPSS 0.006
CVE-2022-25259
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
Published 2022-02-25 · Modified
6.1EPSS 0.006
CVE-2021-37541
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
Published 2021-08-06 · Modified
6.1EPSS 0.006
CVE-2022-29811
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
Published 2022-04-28 · Modified
6.1EPSS 0.005
CVE-2022-48429
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
Published 2023-03-27 · Modified
5.4EPSS 0.006
CVE-2024-38507
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible
Published 2024-06-18 · Modified
5.4EPSS 0.002
CVE-2024-50573
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
Published 2024-10-28 · Analyzed
5.4EPSS 0.002
CVE-2019-14955
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
Published 2019-10-01 · Modified
5.3EPSS 0.009
CVE-2019-18360
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
Published 2019-10-31 · Modified
5.3EPSS 0.009
CVE-2021-25760
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
Published 2021-02-03 · Modified
5.3EPSS 0.009
CVE-2022-34894
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
Published 2022-07-01 · Modified
5.3EPSS 0.006
CVE-2025-64681
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
Published 2025-11-10 · Analyzed
3.7EPSS 0.002
CVE-2025-64682
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
Published 2025-11-10 · Analyzed
3.7EPSS 0.002