CVE-2026-100262: High severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18991
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with read-only access to a YouTrack project can exploit it. No user interaction is required.
2
What can an attacker change?
An attacker can overwrite notification templates for projects to which they have only read-only access. The available data does not specify which template types or notification recipients are affected.
3
Are versions 2026.2.18991 and later affected?
The issue affects JetBrains YouTrack versions before 2026.2.18991. The provided data indicates that version 2026.2.18991 is not within the affected version range.