CVE-2026-100258: Medium severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18991
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access is required to exploit this issue?
An attacker needs low-level authenticated privileges, specifically read-only user access. No user interaction is required.
2
What is the expected security impact?
The impact is limited to confidentiality: a read-only user may be able to view project settings. The supplied severity vector indicates no integrity or availability impact.
3
Can this be exploited remotely?
Yes. The attack vector is network-based and has low attack complexity.