Threat reportVulnerabilityTL-2026-1069
Multiple JetBrains Product Vulnerabilities: Account Takeover, Privilege Escalation, and RCE Across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCity
Multiple JetBrains Product Vulnerabilities (TL-2026-1069), also tracked as JetBrains May-June 2026 Security Patch Cluster, is a high-severity software vulnerability scored CVSS 9.8, first published 2026-07-02. It has no confirmed attribution, affects JetBrains Hub, references 15 CVEs (CVE-2026-25848, CVE-2026-53914, CVE-2026-53915), maps to 24 MITRE ATT&CK techniques (T1005, T1059, T1068), and is covered by 9 detection rules and 21 indicators of compromise.
- CVSS
- 9.8/10High
- CVEs
- 15Referenced vulnerabilities
- Techniques
- 24MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1069
- Threat ID
- TL-2026-1069
- Also known as
- JetBrains May-June 2026 Security Patch Cluster
- Severity
- HIGH
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, softwaredevelopment, finance, government administration, health, criticalinfrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
How Multiple JetBrains Product Vulnerabilities works
JetBrains patched a cluster of vulnerabilities across its developer-tool ecosystem (Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, TeamCity) spanning authentication bypass, privilege escalation, information disclosure, and multiple remote-code-execution primitives. The flaws chain plausibly: identity/SSO compromise in Hub or YouTrack combined with RCE in TeamCity or IntelliJ IDEA enables end-to-end takeover of a software supply chain, from developer workstation to CI/CD build infrastructure.
JetBrains disclosed and fixed a wide-ranging set of security issues affecting its identity/administration hub (Hub), issue tracker (YouTrack), the Kotlin compiler toolchain, the GoLand IDE, IntelliJ IDEA, and the TeamCity CI/CD server, largely in the May-June 2026 patch cycle. The cluster spans several distinct root causes: (1) authentication and authorization weaknesses in Hub and YouTrack, including a critical (CVSS 9.8) authentication bypass allowing unauthenticated administrative actions (CVE-2026-25848, fixed in Hub 2025.3.119807), plus multiple YouTrack access-control and information-disclosure bugs (CVE-2026-49369, CVE-2026-49370, CVE-2026-49385, CVE-2026-49386); (2) unsafe deserialization in the Kotlin compiler's build-cache metadata handling enabling arbitrary code execution during build operations (CVE-2026-53914, CWE-502, fixed in Kotlin 2.4.20); (3) remote code execution in GoLand when opening a project with untrusted, attacker-controlled configuration, driven by external control of file name/path (CVE-2026-53915, CWE-73, CVSS 8.8, fixed in GoLand 2026.1.3); (4) command injection in IntelliJ IDEA's filename-completion subsystem, where unsanitized filenames reach OS command construction (CVE-2026-49366, CWE-78, CVSS 7.8, fixed in IntelliJ IDEA 2026.1.1), and a related template-injection RCE in IntelliJ IDEA's Copyright plugin (CVE-2026-49382, CWE-1336, CVSS 7.8, fixed in IntelliJ IDEA 2026.1); a prior sandbox-bypass RCE was also fixed in YouTrack's template engine for high-privileged users (CVE-2026-33392, CWE-1336, CVSS 7.2); and (5) a cluster of TeamCity CI/CD server flaws fixed in TeamCity 2026.1: RCE via Perforce VCS-root connection settings (CVE-2026-49373, CWE-88, CVSS 7.1), improper authorization exposing build-configuration parameters including database credentials and API keys via the REST API (CVE-2026-49374, CWE-285/CWE-862, critical), insufficient username validation in the SAML SSO plugin enabling identity-provider assertion spoofing and full account takeover including administrator impersonation (CVE-2026-49376, CVSS 6.5), and information disclosure via parameter autocompletion exposing credentials to low-privileged users (CVE-2026-49378). These build on an already-disclosed high-severity TeamCity API-exposure/privilege-escalation issue (CVE-2026-44413, fixed in TeamCity 2026.1) from May 2026. The combined effect across the product line is that an attacker who compromises Hub/YouTrack identity infrastructure, or who gets a victim to open a malicious project/repository in an affected IDE, or who controls a TeamCity VCS connection (e.g., a malicious or compromised Perforce depot), can pivot to code execution on developer workstations or CI/CD build agents — a textbook software-supply-chain attack path. No CVE in this cluster is listed in the CISA Known Exploited Vulnerabilities catalog as of this writing; JetBrains' historical TeamCity path-traversal flaws (CVE-2024-27198/CVE-2024-27199) remain the only JetBrains entries in KEV, added in 2024 and referenced again by CISA in an April 2026 catalog update, underscoring that this vendor's on-premise CI/CD product has a track record of post-disclosure exploitation and should be prioritized for rapid patching.
MITRE ATT&CK techniques used in TL-2026-1069
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery; T1518 Software Discovery
Command and Control
T1071 Application Layer Protocol
Persistence
T1078 Valid Accounts; T1505 Server Software Component
Credential Access
T1110 Brute Force; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1606 Forge Web Credentials
Defense Evasion
T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
Lateral Movement
T1210 Exploitation of Remote Services
Impact
Resource Development
Affected products and versions in Multiple JetBrains Product Vulnerabilities
- JetBrains — Hub
Vulnerable versions: all versions before 2025.3.119807
Fixed in: 2025.3.119807 - JetBrains — YouTrack
Vulnerable versions: all versions before 2025.3.131383; all versions before 2026.1.13162; all versions before 2026.1.13570
Fixed in: 2025.3.131383; 2026.1.13162; 2026.1.13570 - JetBrains — Kotlin (kotlin-compiler)
Vulnerable versions: before 2.4.20
Fixed in: 2.4.20 - JetBrains — GoLand
Vulnerable versions: all versions before 2026.1.3
Fixed in: 2026.1.3 - JetBrains — IntelliJ IDEA
Vulnerable versions: all editions before 2026.1; all editions before 2026.1.1
Fixed in: 2026.1; 2026.1.1 - JetBrains — TeamCity On-Premises
Vulnerable versions: all versions before 2026.1; versions through 2025.11.4
Fixed in: 2026.1
Remediation for Multiple JetBrains Product Vulnerabilities
Patches
- JetBrains Hub 2025.3.119807+
- YouTrack 2026.1.13570+ / 2025.3.131383+
- Kotlin 2.4.20+
- GoLand 2026.1.3+
- IntelliJ IDEA 2026.1.1+
- TeamCity On-Premises 2026.1+
Immediate actions
- Upgrade JetBrains Hub to 2025.3.119807 or later to close the unauthenticated administrative-action bypass (CVE-2026-25848)
- Upgrade YouTrack to 2026.1.13570 (or at minimum 2026.1.13162) to fix access-control and information-disclosure issues (CVE-2026-49369, CVE-2026-49370, CVE-2026-49385, CVE-2026-49386)
- Upgrade YouTrack to 2025.3.131383 or later to close the template-engine sandbox-bypass RCE (CVE-2026-33392)
- Upgrade Kotlin compiler/toolchain to 2.4.20 or later (CVE-2026-53914)
- Upgrade GoLand to 2026.1.3 or later before opening any untrusted project (CVE-2026-53915)
- Upgrade IntelliJ IDEA to 2026.1.1 or later (CVE-2026-49366) and to 2026.1 or later for the Copyright plugin fix (CVE-2026-49382)
- Upgrade TeamCity On-Premises to 2026.1 or later to remediate the Perforce RCE, REST API authorization bypass, SAML spoofing, and parameter-autocomplete disclosure (CVE-2026-49373, CVE-2026-49374, CVE-2026-49376, CVE-2026-49378) as well as the earlier CVE-2026-44413
Workarounds
- Disable the IntelliJ IDEA Copyright plugin until upgraded past 2026.1
- Do not open untrusted/unknown Go projects in GoLand versions prior to 2026.1.3
- Restrict TeamCity Perforce VCS-root creation/editing to trusted, privileged administrators only
- Disable or tightly scope the TeamCity SAML plugin until upgraded to 2026.1
Longer-term hardening
- Enforce MFA/SSO for all JetBrains Hub and YouTrack accounts and disable non-SSO fallback where feasible
- Restrict and monitor direct database access paths to Hub/YouTrack backing stores
- Rotate all credentials, API tokens, and secrets that were ever stored as TeamCity build configuration parameters
- Audit TeamCity SAML SSO configuration and session-establishment logs for anomalous username-assertion values
- Treat IDE project files and VCS connection configuration (including Perforce depots) opened from untrusted or third-party sources as executable content requiring review before opening
- Add JetBrains product versions to vulnerability management / SBOM tracking given repeated CI/CD RCE history (CVE-2024-27198, CVE-2024-27199, CVE-2026-44413, CVE-2026-49373)
CVEs associated with Multiple JetBrains Product Vulnerabilities
Weaknesses (CWE) in Multiple JetBrains Product Vulnerabilities
CWE-287, CWE-502, CWE-73, CWE-78, CWE-863, CWE-201, CWE-88, CWE-285, CWE-862, CWE-639
Timeline of Multiple JetBrains Product Vulnerabilities
- CVE-2026-33392 (YouTrack template-engine sandbox bypass RCE) published, fixed in YouTrack 2025.3.131383.
- JetBrains publishes TeamCity blog advisory for CVE-2026-44413, a high-severity API-exposure/privilege-escalation flaw; recommends upgrade to TeamCity 2026.1.
- JetBrains ships TeamCity 2026.1, remediating the Perforce RCE, REST API authorization bypass, SAML plugin spoofing, and parameter-autocomplete disclosure issues.
- Batch of YouTrack, TeamCity, and Hub CVEs published/reserved: CVE-2026-49369, CVE-2026-49370, CVE-2026-49373, CVE-2026-49374, CVE-2026-49376, CVE-2026-49378, CVE-2026-49382, CVE-2026-49385, CVE-2026-49386, and CVE-2026-25848 (Hub critical auth bypass, CVSS 9.8).
- CVE-2026-49366 (IntelliJ IDEA filename-completion command injection) and CVE-2026-49382 (Copyright plugin template injection RCE) published; fixed in IntelliJ IDEA 2026.1.1 and 2026.1 respectively.
- CVE-2026-53915 (GoLand untrusted project-configuration RCE) published, fixed in GoLand 2026.1.3.
- CVE-2026-53914 (Kotlin compiler unsafe deserialization in build-cache metadata) published, fixed in Kotlin 2.4.20.
- TL-Intel-Harness HUNT phase ingests the article and creates threat skeleton TL-2026-1069; RESEARCH phase correlates it against 15 individually disclosed CVEs across six JetBrains products.
- Cyber Security News publishes a roundup article covering the combined JetBrains vulnerability cluster across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCity, prompting this threat-intel record.
Sources cited for Multiple JetBrains Product Vulnerabilities
- JetBrains Vulnerabilities
- Fixed security issues
- CVE-2026-53914: CWE-502 in JetBrains Kotlin
- NVD - CVE-2026-53915
- NVD - CVE-2026-49370
- NVD - CVE-2026-49369
- NVD - CVE-2026-49385
- NVD - CVE-2026-49386
- NVD - CVE-2026-33392
- CVE-2026-49366: JetBrains IntelliJ IDEA RCE Vulnerability
- CVE-2026-49382: JetBrains IntelliJ IDEA RCE Vulnerability
- CVE-2026-49373 | THREATINT
- JetBrains TeamCity, Improper Authorization (CWE-285), CVE-2026-49374
- TeamCity, Improper Input Validation, CVE-2026-49376
- CVE-2026-25848 - JetBrains Hub Authentication Bypass Vulnerability
Detection coverage for TL-2026-1069
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1069 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.