CVE-2026-103495: Medium severity JetBrains YouTrack vulnerability
Published Oct 1, 2026
·Updated
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
Affected Software
2 affected components
JetBrains YouTrack<2026.2.19422
JetBrains YouTrack<2026.2.19422
Event History
Oct 1, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs low-privileged access to the YouTrack instance. The attack can be performed over the network and does not require user interaction.
2
What versions need to be remediated?
JetBrains YouTrack versions before 2026.2.19422 are affected. Upgrade to version 2026.2.19422 or later.
3
What is the expected impact?
The issue can allow an authorized low-privileged user to reload translation catalogs without proper authorization. The published severity vector indicates an availability impact, with no stated confidentiality or integrity impact.