CVE-2026-100263: XSS
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18991
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to cause a victim to interact with content containing injected HTML. The issue can be triggered through the User-Agent HTTP header and requires no attacker privileges.
2
Which YouTrack versions are affected?
YouTrack versions before 2026.2.18991 are affected. Updating to 2026.2.18991 or a later version addresses the reported issue.
3
What is the likely impact if exploitation succeeds?
The reported vector is stored HTML injection/XSS. The supplied severity vector indicates low confidentiality impact, no integrity impact, and no availability impact; impact can extend beyond the initially affected security scope.