TL;DR
Software developer JetBrains has resolved 29 security flaws across its enterprise ecosystem. These JetBrains vulnerabilities include two critical flaws that threaten administrative control. Consequently, administrators must apply the latest software updates to block potential intrusions.
- Total: 6 CVEs
- Severity: 2 Critical · 3 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-86478
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-86478 | 9.8 | CWE-290 | 2025.3.161254, 2026.1.14042 | Not exploited |
| CVE-2026-86480 | 9.8 | CWE-306 | 2026.2.52442 | Not exploited |
| CVE-2026-86502 | 8.4 | CWE-306 | 2026.2.2 | Not exploited |
| CVE-2026-86479 | 8.1 | CWE-862 | 2026.2.18788, 2026.1.14055, 2025.3.161254 | Not exploited |
| CVE-2026-86504 | 7.8 | CWE-829 | 2026.2.2 | Not exploited |
| CVE-2026-86506 | 5.9 | CWE-306 | 2026.2.2.1 | Not exploited |
Why It Matters
The most severe bugs carry maximum CVSS severity scores of 9.8. Specifically, the flaw in Hub allows complete administrative compromise without authentication. Furthermore, the vulnerability in YouTrack Helpdesk permits unauthorized attackers to hijack user accounts. Millions of developers and thousands of enterprise development teams use JetBrains collaboration tools globally. Therefore, leaving these collaboration servers exposed creates high operational danger. Currently, researchers have confirmed no active in-the-wild exploitation or public exploit code.
How the Attack Works
In YouTrack, the vulnerability stems from improper authentication mechanisms within the Helpdesk module. According to the vendor, “Improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address.” An attacker supplies a forged email to claim ownership of existing accounts.
Meanwhile, Hub contains an authentication bypass flaw in service registration. The vendor advisory confirmed that “an unauthenticated attacker could register a trusted service and gain superuser privileges.” By registering a rogue service, the attacker acquires top-level authority over the identity platform. In addition, flaws in IntelliJ IDEA permit code execution through unauthenticated gRPC endpoints and Dev Container builds.
Affected Versions
These JetBrains vulnerabilities impact several products across multiple releases. YouTrack versions prior to 2025.3.161254, 2026.1.14042, and 2026.2.18634 remain affected. Hub releases before version 2026.2.52442 contain the superuser privilege flaw. Finally, IntelliJ IDEA versions before 2026.2.2 and GoLand versions before 2026.2.2.1 carry local execution and data exposure risks.
Patch and Mitigation Steps
Administrators should upgrade affected installations to the patched builds immediately. You can review the full advisory on the JetBrains fixed issues page. Furthermore, restrict network exposure for administrative web interfaces. Place internal collaboration servers behind trusted virtual private networks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!