Email Spoofing Vulnerability in JetBrains Hub
CVE-2026-100266

7.7HIGH

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-100266?

JetBrains Hub, before version 2026.2.52366, contains an authorization bypass vulnerability that allows authenticated users to send arbitrary emails from the server's trusted address. This could lead to potential misuse of the system, as unauthorized parties may leverage trusted email communication for phishing attempts or other malicious activities.

Affected Version(s)

Hub 0 < 2026.2.52366

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.