CVE-2026-100278: Medium severity JetBrains YouTrack vulnerability
Published Sep 30, 2026
·Updated
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
Affected Software
1 affected component
JetBrains YouTrack<2026.2.19197
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.19197
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who could exploit this issue?
An authenticated YouTrack user with restricted permission could exploit it. The attacker does not need user interaction.
2
What is the impact of successful exploitation?
The attacker could edit and hide comments made by other users, affecting comment integrity. The provided data does not indicate confidentiality or availability impact.
3
Which deployments are affected?
JetBrains YouTrack versions before 2026.2.19197 are affected. The provided data does not state whether any particular default configuration changes exposure.