Threat reportVulnerabilityTL-2026-1069

Multiple JetBrains Product Vulnerabilities: Account Takeover, Privilege Escalation, and RCE Across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCity

highACTIVE

Multiple JetBrains Product Vulnerabilities (TL-2026-1069), also tracked as JetBrains May-June 2026 Security Patch Cluster, is a high-severity software vulnerability scored CVSS 9.8, first published 2026-07-02. It has no confirmed attribution, affects JetBrains Hub, references 15 CVEs (CVE-2026-25848, CVE-2026-53914, CVE-2026-53915), maps to 24 MITRE ATT&CK techniques (T1005, T1059, T1068), and is covered by 9 detection rules and 21 indicators of compromise.

CVSS
9.8/10High
CVEs
15Referenced vulnerabilities
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-1069

Threat ID
TL-2026-1069
Also known as
JetBrains May-June 2026 Security Patch Cluster
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, softwaredevelopment, finance, government administration, health, criticalinfrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
21

How Multiple JetBrains Product Vulnerabilities works

JetBrains patched a cluster of vulnerabilities across its developer-tool ecosystem (Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, TeamCity) spanning authentication bypass, privilege escalation, information disclosure, and multiple remote-code-execution primitives. The flaws chain plausibly: identity/SSO compromise in Hub or YouTrack combined with RCE in TeamCity or IntelliJ IDEA enables end-to-end takeover of a software supply chain, from developer workstation to CI/CD build infrastructure.

JetBrains disclosed and fixed a wide-ranging set of security issues affecting its identity/administration hub (Hub), issue tracker (YouTrack), the Kotlin compiler toolchain, the GoLand IDE, IntelliJ IDEA, and the TeamCity CI/CD server, largely in the May-June 2026 patch cycle. The cluster spans several distinct root causes: (1) authentication and authorization weaknesses in Hub and YouTrack, including a critical (CVSS 9.8) authentication bypass allowing unauthenticated administrative actions (CVE-2026-25848, fixed in Hub 2025.3.119807), plus multiple YouTrack access-control and information-disclosure bugs (CVE-2026-49369, CVE-2026-49370, CVE-2026-49385, CVE-2026-49386); (2) unsafe deserialization in the Kotlin compiler's build-cache metadata handling enabling arbitrary code execution during build operations (CVE-2026-53914, CWE-502, fixed in Kotlin 2.4.20); (3) remote code execution in GoLand when opening a project with untrusted, attacker-controlled configuration, driven by external control of file name/path (CVE-2026-53915, CWE-73, CVSS 8.8, fixed in GoLand 2026.1.3); (4) command injection in IntelliJ IDEA's filename-completion subsystem, where unsanitized filenames reach OS command construction (CVE-2026-49366, CWE-78, CVSS 7.8, fixed in IntelliJ IDEA 2026.1.1), and a related template-injection RCE in IntelliJ IDEA's Copyright plugin (CVE-2026-49382, CWE-1336, CVSS 7.8, fixed in IntelliJ IDEA 2026.1); a prior sandbox-bypass RCE was also fixed in YouTrack's template engine for high-privileged users (CVE-2026-33392, CWE-1336, CVSS 7.2); and (5) a cluster of TeamCity CI/CD server flaws fixed in TeamCity 2026.1: RCE via Perforce VCS-root connection settings (CVE-2026-49373, CWE-88, CVSS 7.1), improper authorization exposing build-configuration parameters including database credentials and API keys via the REST API (CVE-2026-49374, CWE-285/CWE-862, critical), insufficient username validation in the SAML SSO plugin enabling identity-provider assertion spoofing and full account takeover including administrator impersonation (CVE-2026-49376, CVSS 6.5), and information disclosure via parameter autocompletion exposing credentials to low-privileged users (CVE-2026-49378). These build on an already-disclosed high-severity TeamCity API-exposure/privilege-escalation issue (CVE-2026-44413, fixed in TeamCity 2026.1) from May 2026. The combined effect across the product line is that an attacker who compromises Hub/YouTrack identity infrastructure, or who gets a victim to open a malicious project/repository in an affected IDE, or who controls a TeamCity VCS connection (e.g., a malicious or compromised Perforce depot), can pivot to code execution on developer workstations or CI/CD build agents — a textbook software-supply-chain attack path. No CVE in this cluster is listed in the CISA Known Exploited Vulnerabilities catalog as of this writing; JetBrains' historical TeamCity path-traversal flaws (CVE-2024-27198/CVE-2024-27199) remain the only JetBrains entries in KEV, added in 2024 and referenced again by CISA in an April 2026 catalog update, underscoring that this vendor's on-premise CI/CD product has a track record of post-disclosure exploitation and should be prioritized for rapid patching.

MITRE ATT&CK techniques used in TL-2026-1069

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts

Discovery

T1069 Permission Groups Discovery; T1087 Account Discovery; T1518 Software Discovery

Command and Control

T1071 Application Layer Protocol

Persistence

T1078 Valid Accounts; T1505 Server Software Component

Credential Access

T1110 Brute Force; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1606 Forge Web Credentials

Defense Evasion

T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1565 Data Manipulation

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in Multiple JetBrains Product Vulnerabilities

  • JetBrains — Hub
    Vulnerable versions: all versions before 2025.3.119807
    Fixed in: 2025.3.119807
  • JetBrains — YouTrack
    Vulnerable versions: all versions before 2025.3.131383; all versions before 2026.1.13162; all versions before 2026.1.13570
    Fixed in: 2025.3.131383; 2026.1.13162; 2026.1.13570
  • JetBrains — Kotlin (kotlin-compiler)
    Vulnerable versions: before 2.4.20
    Fixed in: 2.4.20
  • JetBrains — GoLand
    Vulnerable versions: all versions before 2026.1.3
    Fixed in: 2026.1.3
  • JetBrains — IntelliJ IDEA
    Vulnerable versions: all editions before 2026.1; all editions before 2026.1.1
    Fixed in: 2026.1; 2026.1.1
  • JetBrains — TeamCity On-Premises
    Vulnerable versions: all versions before 2026.1; versions through 2025.11.4
    Fixed in: 2026.1

Remediation for Multiple JetBrains Product Vulnerabilities

Patches

  • JetBrains Hub 2025.3.119807+
  • YouTrack 2026.1.13570+ / 2025.3.131383+
  • Kotlin 2.4.20+
  • GoLand 2026.1.3+
  • IntelliJ IDEA 2026.1.1+
  • TeamCity On-Premises 2026.1+

Immediate actions

  • Upgrade JetBrains Hub to 2025.3.119807 or later to close the unauthenticated administrative-action bypass (CVE-2026-25848)
  • Upgrade YouTrack to 2026.1.13570 (or at minimum 2026.1.13162) to fix access-control and information-disclosure issues (CVE-2026-49369, CVE-2026-49370, CVE-2026-49385, CVE-2026-49386)
  • Upgrade YouTrack to 2025.3.131383 or later to close the template-engine sandbox-bypass RCE (CVE-2026-33392)
  • Upgrade Kotlin compiler/toolchain to 2.4.20 or later (CVE-2026-53914)
  • Upgrade GoLand to 2026.1.3 or later before opening any untrusted project (CVE-2026-53915)
  • Upgrade IntelliJ IDEA to 2026.1.1 or later (CVE-2026-49366) and to 2026.1 or later for the Copyright plugin fix (CVE-2026-49382)
  • Upgrade TeamCity On-Premises to 2026.1 or later to remediate the Perforce RCE, REST API authorization bypass, SAML spoofing, and parameter-autocomplete disclosure (CVE-2026-49373, CVE-2026-49374, CVE-2026-49376, CVE-2026-49378) as well as the earlier CVE-2026-44413

Workarounds

  • Disable the IntelliJ IDEA Copyright plugin until upgraded past 2026.1
  • Do not open untrusted/unknown Go projects in GoLand versions prior to 2026.1.3
  • Restrict TeamCity Perforce VCS-root creation/editing to trusted, privileged administrators only
  • Disable or tightly scope the TeamCity SAML plugin until upgraded to 2026.1

Longer-term hardening

  • Enforce MFA/SSO for all JetBrains Hub and YouTrack accounts and disable non-SSO fallback where feasible
  • Restrict and monitor direct database access paths to Hub/YouTrack backing stores
  • Rotate all credentials, API tokens, and secrets that were ever stored as TeamCity build configuration parameters
  • Audit TeamCity SAML SSO configuration and session-establishment logs for anomalous username-assertion values
  • Treat IDE project files and VCS connection configuration (including Perforce depots) opened from untrusted or third-party sources as executable content requiring review before opening
  • Add JetBrains product versions to vulnerability management / SBOM tracking given repeated CI/CD RCE history (CVE-2024-27198, CVE-2024-27199, CVE-2026-44413, CVE-2026-49373)

CVEs associated with Multiple JetBrains Product Vulnerabilities

Weaknesses (CWE) in Multiple JetBrains Product Vulnerabilities

CWE-287, CWE-502, CWE-73, CWE-78, CWE-863, CWE-201, CWE-88, CWE-285, CWE-862, CWE-639

Timeline of Multiple JetBrains Product Vulnerabilities

  • CVE-2026-33392 (YouTrack template-engine sandbox bypass RCE) published, fixed in YouTrack 2025.3.131383.
  • JetBrains publishes TeamCity blog advisory for CVE-2026-44413, a high-severity API-exposure/privilege-escalation flaw; recommends upgrade to TeamCity 2026.1.
  • JetBrains ships TeamCity 2026.1, remediating the Perforce RCE, REST API authorization bypass, SAML plugin spoofing, and parameter-autocomplete disclosure issues.
  • Batch of YouTrack, TeamCity, and Hub CVEs published/reserved: CVE-2026-49369, CVE-2026-49370, CVE-2026-49373, CVE-2026-49374, CVE-2026-49376, CVE-2026-49378, CVE-2026-49382, CVE-2026-49385, CVE-2026-49386, and CVE-2026-25848 (Hub critical auth bypass, CVSS 9.8).
  • CVE-2026-49366 (IntelliJ IDEA filename-completion command injection) and CVE-2026-49382 (Copyright plugin template injection RCE) published; fixed in IntelliJ IDEA 2026.1.1 and 2026.1 respectively.
  • CVE-2026-53915 (GoLand untrusted project-configuration RCE) published, fixed in GoLand 2026.1.3.
  • CVE-2026-53914 (Kotlin compiler unsafe deserialization in build-cache metadata) published, fixed in Kotlin 2.4.20.
  • TL-Intel-Harness HUNT phase ingests the article and creates threat skeleton TL-2026-1069; RESEARCH phase correlates it against 15 individually disclosed CVEs across six JetBrains products.
  • Cyber Security News publishes a roundup article covering the combined JetBrains vulnerability cluster across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCity, prompting this threat-intel record.

Sources cited for Multiple JetBrains Product Vulnerabilities

Detection coverage for TL-2026-1069

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1069 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats