Jetbrains
Jetbrains Youtrack: vulnerabilidades y CVE
Jetbrains Youtrack tiene 179 vulnerabilidades publicadas, 82 de ellas en los últimos 12 meses. 15 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE179
Últimos 12 meses82
Críticas15
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-103497 | Media (5.5) | 0.15% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration |
| CVE-2026-103496 | Media (5.4) | 0.14% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications |
| CVE-2026-103495 | Media (4.3) | 0.19% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs |
| CVE-2026-103494 | Media (6.6) | 0.21% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes |
| CVE-2026-103493 | Alta (8.1) | 0.22% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible |
| CVE-2026-103492 | Media (6.5) | 0.68% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments |
| CVE-2026-103491 | Media (6.5) | 0.20% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues |
| CVE-2026-103490 | Alta (7.2) | 0.43% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links |
| CVE-2026-103489 | Media (5.4) | 0.14% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible |
| CVE-2026-103488 | Alta (7.1) | 0.28% | — | 1 oct 2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues |
| CVE-2026-100280 | Media (4.3) | 0.17% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible |
| CVE-2026-100279 | Media (6.5) | 0.25% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials |
| CVE-2026-100278 | Media (4.9) | 0.24% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments |
| CVE-2026-100277 | Crítica (9.8) | 0.28% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature |
| CVE-2026-100276 | Alta (7.5) | 0.22% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action |
| CVE-2026-100275 | Media (4.8) | 0.19% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible |
| CVE-2026-100274 | Media (6.5) | 0.84% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template |
| CVE-2026-100273 | Crítica (9.8) | 0.30% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution |
| CVE-2026-100272 | Media (4.9) | 0.29% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues |
| CVE-2026-100271 | Baja (2.7) | 0.23% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects |
| CVE-2026-100270 | Baja (2.7) | 0.17% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations |
| CVE-2026-100269 | Media (4.3) | 0.20% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed |
| CVE-2026-100268 | Baja (2.7) | 0.23% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates |
| CVE-2026-100267 | Media (5.9) | 0.29% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters |
| CVE-2026-100264 | Baja (2.7) | 0.23% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host |
| CVE-2026-100263 | Media (6.1) | 0.19% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible |
| CVE-2026-100262 | Alta (7.1) | 0.21% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates |
| CVE-2026-100261 | Media (5.4) | 0.18% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission |
| CVE-2026-100260 | Media (5.3) | 0.27% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset |
| CVE-2026-100259 | Media (4.3) | 0.19% | — | 30 sept 2026 | In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.