CVE-2026-100277: High severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
Affected Software
1 affected component
JetBrains YouTrack<2026.2.19197
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker obtain to exploit this issue?
The attacker needs a notification signature that can be replayed. No authentication or user interaction is required, but exploitation has high attack complexity.
2
Which deployments should be remediated?
JetBrains YouTrack versions before 2026.2.19197 are affected. Upgrade to 2026.2.19197 or a later version.
3
What is the potential impact of successful exploitation?
Successful replay can result in account takeover. The vulnerability can affect confidentiality and integrity at a high level and has a limited availability impact.