CVE-2026-100271: Low severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
Affected Software
1 affected component
JetBrains YouTrack<2026.2.19197
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated YouTrack user can exploit it. The issue requires high privileges according to the CVSS vector, but no user interaction is needed.
2
What is the impact of successful exploitation?
An affected user may access information belonging to other projects. The reported impact is limited to confidentiality; no integrity or availability impact is indicated.
3
Which deployments are affected?
JetBrains YouTrack versions before 2026.2.19197 are affected. The provided information does not identify any configuration prerequisite or exclusion.