CVE-2026-100269: Medium severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
Affected Software
1 affected component
JetBrains YouTrack<2026.2.19197
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who could exploit this issue?
An attacker needs low-privileged access to YouTrack. The CVSS vector indicates the issue is remotely exploitable, requires no user interaction, and has low attack complexity.
2
Which environments are affected?
The issue affects JetBrains YouTrack versions before 2026.2.19197 when a helpdesk project relies on its Authorized Reporters list.
3
What is the likely impact of successful exploitation?
Successful exploitation can bypass the Authorized Reporters restriction for a helpdesk project. The supplied CVSS vector indicates an integrity impact, with no stated confidentiality or availability impact.