CVE-2026-100264: Low severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18991
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs high-level privileges in YouTrack, because the vulnerability requires PR:H. The issue can be exploited remotely without user interaction.
2
What capability does exploitation provide?
Exploitation may disclose stored SMTP server credentials. The stated impact is limited to confidentiality; integrity and availability are not affected.
3
Which deployments are affected?
JetBrains YouTrack versions before 2026.2.18991 are affected. The issue is associated with changing the configured SMTP server host.