CVE-2026-57922
- EPSS 0.14%
- Veröffentlicht 26.06.2026 12:38:17
- Zuletzt bearbeitet 27.06.2026 19:33:20
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
CVE-2026-49385
- EPSS 0.22%
- Veröffentlicht 29.05.2026 18:15:54
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
CVE-2026-49386
- EPSS 0.26%
- Veröffentlicht 29.05.2026 18:15:54
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
CVE-2026-49370
- EPSS 0.25%
- Veröffentlicht 29.05.2026 18:15:47
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
CVE-2026-49368
- EPSS 0.21%
- Veröffentlicht 29.05.2026 18:15:46
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
CVE-2026-49369
- EPSS 0.21%
- Veröffentlicht 29.05.2026 18:15:46
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
CVE-2026-33392
- EPSS 0.43%
- Veröffentlicht 17.04.2026 07:46:11
- Zuletzt bearbeitet 20.04.2026 20:18:22
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
CVE-2026-28193
- EPSS 0.25%
- Veröffentlicht 25.02.2026 12:57:27
- Zuletzt bearbeitet 26.02.2026 15:59:53
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
CVE-2026-25846
- EPSS 0.87%
- Veröffentlicht 09.02.2026 10:38:59
- Zuletzt bearbeitet 18.02.2026 20:48:14
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
CVE-2025-64773
- EPSS 0.22%
- Veröffentlicht 11.11.2025 15:23:19
- Zuletzt bearbeitet 11.12.2025 19:16:00
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit