CVE-2026-100276: Medium severity JetBrains YouTrack vulnerability
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.19197
Event History
Frequently Asked Questions
Which YouTrack deployments are affected?
JetBrains YouTrack versions before 2026.2.19197 are affected. Deployments running 2026.2.19197 or later are not identified as affected by the provided information.
What access and conditions does an attacker need?
The issue can be exploited by a guest user and does not require privileges or user interaction. Exploitation has high attack complexity and involves a workflow action that has a visibility restriction.
What is the expected security impact?
The vulnerability affects integrity: a guest user could remove a workflow action's visibility restriction and run that action. No confidentiality or availability impact is indicated.