CVE-2026-100258
- EPSS 0.64%
- Veröffentlicht 30.09.2026 15:17:47
- Zuletzt bearbeitet 02.10.2026 20:36:57
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
CVE-2026-100257
- EPSS 0.21%
- Veröffentlicht 30.09.2026 15:17:46
- Zuletzt bearbeitet 02.10.2026 20:42:55
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVE-2026-86497
- EPSS 0.27%
- Veröffentlicht 07.09.2026 17:17:28
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
CVE-2026-86498
- EPSS 0.17%
- Veröffentlicht 07.09.2026 17:17:28
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
CVE-2026-86499
- EPSS 0.16%
- Veröffentlicht 07.09.2026 17:17:28
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
CVE-2026-86500
- EPSS 0.15%
- Veröffentlicht 07.09.2026 17:17:28
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
CVE-2026-86488
- EPSS 0.2%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
CVE-2026-86489
- EPSS 0.2%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
CVE-2026-86490
- EPSS 0.17%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
CVE-2026-86491
- EPSS 0.14%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads