CVE-2026-103488: High severity JetBrains YouTrack vulnerability
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.19422
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated YouTrack user may be able to exploit it. The issue does not require user interaction and is reachable over the network.
What access could an attacker gain?
An attacker could add themselves to project teams and then access issues restricted to those teams. The reported impact includes high confidentiality impact and low integrity impact.
Which versions are affected?
JetBrains YouTrack versions before 2026.2.19422 are affected.
How can I determine whether my instance may be vulnerable?
Check the deployed YouTrack version. Instances running a version earlier than 2026.2.19422 may be affected; also review project team membership changes and access to restricted issues by unexpected users.