CVE-2026-103496: Medium severity JetBrains YouTrack vulnerability
Published Oct 1, 2026
·Updated
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
Affected Software
2 affected components
JetBrains YouTrack<2026.2.19422
JetBrains YouTrack<2026.2.19422
Event History
Oct 1, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs a low-privileged authenticated account. No user interaction is required.
2
What information could be exposed?
A successful exploit can allow reading notifications belonging to other users through inbox threads. The listed impact is low confidentiality and low integrity impact.
3
Which versions should be remediated?
JetBrains YouTrack versions before 2026.2.19422 are affected. Upgrade to 2026.2.19422 or a later version.