CVE-2026-103491: Medium severity JetBrains YouTrack vulnerability
Published Oct 1, 2026
·Updated
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
Affected Software
1 affected component
JetBrains YouTrack<2026.2.19422
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.19422
Event History
Oct 1, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs a low-privileged authenticated account and network access to the affected instance. No user interaction is required.
2
What information could be exposed?
The issue activities API could allow reading issues that are restricted to the attacker under normal access controls. The reported impact is confidentiality-only, with no integrity or availability impact stated.
3
What version should be used to remediate this issue?
Upgrade JetBrains YouTrack to version 2026.2.19422 or later. Versions before 2026.2.19422 are affected.