CVE-2026-75044
- EPSS 0.23%
- Veröffentlicht 17.08.2026 15:54:34
- Zuletzt bearbeitet 15.09.2026 17:46:57
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
CVE-2026-75045
- EPSS 0.3%
- Veröffentlicht 17.08.2026 15:54:34
- Zuletzt bearbeitet 15.09.2026 17:46:16
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVE-2026-62422
- EPSS 0.33%
- Veröffentlicht 14.07.2026 10:17:59
- Zuletzt bearbeitet 12.08.2026 17:07:35
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
CVE-2026-61492
- EPSS 0.39%
- Veröffentlicht 10.07.2026 14:19:00
- Zuletzt bearbeitet 10.07.2026 18:57:39
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
CVE-2026-59791
- EPSS 0.14%
- Veröffentlicht 10.07.2026 14:18:56
- Zuletzt bearbeitet 10.07.2026 18:58:17
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
CVE-2026-57925
- EPSS 0.17%
- Veröffentlicht 26.06.2026 12:38:19
- Zuletzt bearbeitet 27.06.2026 19:29:53
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
CVE-2026-57926
- EPSS 0.19%
- Veröffentlicht 26.06.2026 12:38:19
- Zuletzt bearbeitet 27.06.2026 18:51:07
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-57923
- EPSS 0.16%
- Veröffentlicht 26.06.2026 12:38:18
- Zuletzt bearbeitet 27.06.2026 19:32:58
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
CVE-2026-57924
- EPSS 0.17%
- Veröffentlicht 26.06.2026 12:38:18
- Zuletzt bearbeitet 27.06.2026 19:31:32
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
CVE-2026-57921
- EPSS 0.18%
- Veröffentlicht 26.06.2026 12:38:17
- Zuletzt bearbeitet 27.06.2026 19:35:26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint