CVE-2026-100260: Medium severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18991
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which YouTrack deployments should be treated as affected?
JetBrains YouTrack versions before 2026.2.18991 are affected in relation to mailbox integration. Verify the deployed YouTrack version and whether mailbox integration is in use.
2
What does the available severity data indicate about exploitation requirements and impact?
The CVSS vector indicates network-based exploitation with low attack complexity, no required privileges, and no user interaction. The listed impact is limited to low integrity impact, with no confidentiality or availability impact indicated.