JetBrains YouTrack
54 known vulnerabilities in JetBrains YouTrack, 3 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-103497 CVSS 5.5 medium In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
- CVE-2026-103496 CVSS 5.4 medium In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
- CVE-2026-103495 CVSS 4.3 medium In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
- CVE-2026-103494 CVSS 6.6 medium In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
- CVE-2026-103493 CVSS 8.1 high In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
- CVE-2026-103492 CVSS 6.5 medium In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
- CVE-2026-103491 CVSS 6.5 medium In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
- CVE-2026-103490 CVSS 7.2 high In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
- CVE-2026-103489 CVSS 5.4 medium In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
- CVE-2026-103488 CVSS 7.1 high In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access…
- CVE-2026-100280 CVSS 4.3 medium In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
- CVE-2026-100279 CVSS 6.5 medium In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
- CVE-2026-100278 CVSS 4.9 medium In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
- CVE-2026-100277 CVSS 9.8 critical In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
- CVE-2026-100276 CVSS 7.5 high In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
- CVE-2026-100275 CVSS 4.8 medium In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
- CVE-2026-100274 CVSS 6.5 medium In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
- CVE-2026-100273 CVSS 9.8 critical In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
- CVE-2026-100272 CVSS 4.9 medium In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to…
- CVE-2026-100271 CVSS 2.7 low In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information…
- CVE-2026-100270 CVSS 2.7 low In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import…
- CVE-2026-100269 CVSS 4.3 medium In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
- CVE-2026-100268 CVSS 2.7 low In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
- CVE-2026-100267 CVSS 5.9 medium In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
- CVE-2026-100264 CVSS 2.7 low In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
- CVE-2026-100263 CVSS 6.1 medium In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
- CVE-2026-100262 CVSS 7.1 high In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project…
- CVE-2026-100261 CVSS 5.4 medium In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
- CVE-2026-100260 CVSS 5.3 medium In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
- CVE-2026-100259 CVSS 4.3 medium In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access