JETBRAINS has disclosed a batch of 29 security flaws across its Hub and YouTrack offerings, together with related issues in accompanying tooling. The round-up lists six CVEs across the affected products, with two rated as critical. CVSS v3 scores for the highest-severity flaws reach 9.8. Notably, CVE-2026-86478 (Hub) and CVE-2026-86480 (Hub/YouTrack) feature the most serious impact, including unauthenticated administrative escalation and account takeover possibilities.
At the time of reporting, researchers confirmed no active exploitation in the wild, though the flaws are described as high-risk and warrant prompt remediation through updates.
In YouTrack, the issue stems from improper authentication within the Helpdesk module, described as allowing unauthenticated account takeover via a self-asserted email address—attackers could forge an email to claim ownership of existing accounts. In Hub, an authentication bypass vulnerability in service registration could let an unauthenticated attacker register a trusted service and gain superuser privileges, effectively taking control of the identity platform.
Additional flaws in IntelliJ IDEA enable code execution via unauthenticated gRPC endpoints, and similar concerns affect GoLand. Affected versions include YouTrack before 2025.3.161254, 2026.1.14042, and 2026.2.18634; Hub before 2026.2.52442; IntelliJ IDEA before 2026.2.2; and GoLand before 2026.2.2.1.
JetBrains urges administrators to upgrade to patched builds immediately and to limit exposure of administrative interfaces. Details and fixed builds are available on the JetBrains advisory page.