« Back to list

Jetbrains

Jetbrains Youtrack: vulnerabilities and CVEs

Jetbrains Youtrack has 179 published vulnerabilities, 82 of them in the last 12 months. 15 are rated critical and 0 are listed by CISA as actively exploited.

CVEs179
Last 12 months82
Critical15
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-103497Medium (5.5)0.15%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVE-2026-103496Medium (5.4)0.14%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVE-2026-103495Medium (4.3)0.19%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVE-2026-103494Medium (6.6)0.21%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVE-2026-103493High (8.1)0.22%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVE-2026-103492Medium (6.5)0.68%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVE-2026-103491Medium (6.5)0.20%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVE-2026-103490High (7.2)0.43%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVE-2026-103489Low (2)0.14%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVE-2026-103488High (7.1)0.28%—Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVE-2026-100280Medium (4.3)0.17%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-100279Medium (6.5)0.25%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
CVE-2026-100278Medium (4.9)0.24%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVE-2026-100277Critical (9.8)0.28%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100276High (7.5)0.22%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVE-2026-100275Medium (4.8)0.19%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2026-100274Medium (6.5)0.84%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
CVE-2026-100273Critical (9.8)0.30%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVE-2026-100272Medium (4.9)0.29%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
CVE-2026-100271Low (2.7)0.23%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
CVE-2026-100270Low (2.7)0.17%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
CVE-2026-100269Medium (4.3)0.20%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
CVE-2026-100268Low (2.7)0.23%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-100267Medium (5.9)0.29%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVE-2026-100264Low (2.7)0.23%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
CVE-2026-100263Medium (6.1)0.19%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVE-2026-100262High (7.1)0.21%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
CVE-2026-100261Medium (5.4)0.18%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVE-2026-100260Medium (5.3)0.27%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
CVE-2026-100259Medium (4.3)0.19%—Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services32
  2. T1190 Exploit Public-Facing Application16
  3. T1078 Valid Accounts15
  4. T1005 Data from Local System8
  5. T1059.007 JavaScript6
  6. T1189 Drive-by Compromise5

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Jetbrains