CVE-2026-100272
- EPSS 0.29%
- Veröffentlicht 30.09.2026 15:17:52
- Zuletzt bearbeitet 02.10.2026 16:32:28
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
CVE-2026-100267
- EPSS 0.29%
- Veröffentlicht 30.09.2026 15:17:51
- Zuletzt bearbeitet 01.10.2026 15:25:01
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVE-2026-100268
- EPSS 0.23%
- Veröffentlicht 30.09.2026 15:17:51
- Zuletzt bearbeitet 01.10.2026 15:57:46
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-100269
- EPSS 0.2%
- Veröffentlicht 30.09.2026 15:17:51
- Zuletzt bearbeitet 01.10.2026 15:59:44
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
CVE-2026-100264
- EPSS 0.23%
- Veröffentlicht 30.09.2026 15:17:50
- Zuletzt bearbeitet 02.10.2026 17:06:04
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
CVE-2026-100262
- EPSS 0.24%
- Veröffentlicht 30.09.2026 15:17:49
- Zuletzt bearbeitet 02.10.2026 20:25:39
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
CVE-2026-100263
- EPSS 0.23%
- Veröffentlicht 30.09.2026 15:17:49
- Zuletzt bearbeitet 02.10.2026 20:23:31
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVE-2026-100259
- EPSS 0.19%
- Veröffentlicht 30.09.2026 15:17:48
- Zuletzt bearbeitet 02.10.2026 20:35:38
In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
CVE-2026-100260
- EPSS 0.27%
- Veröffentlicht 30.09.2026 15:17:48
- Zuletzt bearbeitet 02.10.2026 20:29:06
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
CVE-2026-100261
- EPSS 0.18%
- Veröffentlicht 30.09.2026 15:17:48
- Zuletzt bearbeitet 02.10.2026 20:26:24
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission