CVE-2026-28193: High severity JetBrains YouTrack vulnerability
Published Feb 25, 2026
·Updated
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
Affected Software
2 affected components
JetBrains YouTrack<2025.3.121962
JetBrains YouTrack<2025.3.121962
Event History
Feb 25, 2026
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 18, 58128
Event
via FIRST·04:27 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-28193?
The severity of CVE-2026-28193 is high, as it allows unauthorized requests to the app permissions endpoint in JetBrains YouTrack.
2
How do I fix CVE-2026-28193?
To fix CVE-2026-28193, upgrade JetBrains YouTrack to version 2025.3.121962 or later.
3
What impact does CVE-2026-28193 have on JetBrains YouTrack?
CVE-2026-28193 can lead to potential unauthorized access and manipulation of app permissions within JetBrains YouTrack.
4
Is CVE-2026-28193 present in all versions of JetBrains YouTrack?
CVE-2026-28193 affects all versions of JetBrains YouTrack prior to 2025.3.121962.
5
Who is affected by CVE-2026-28193?
Users and administrators of JetBrains YouTrack versions below 2025.3.121962 are affected by CVE-2026-28193.