CVE-2026-57922: Medium severity JetBrains YouTrack vulnerability
Published Jun 26, 2026
·Updated
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Affected Software
2 affected components
JetBrains YouTrack<2026.2.16593
JetBrains YouTrack<2026.2.16593
Event History
Jun 26, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57922?
The severity of CVE-2026-57922 is classified as low with a score of 3.1.
2
What does CVE-2026-57922 impact?
CVE-2026-57922 impacts JetBrains YouTrack versions prior to 2026.2.16593.
3
How do I fix CVE-2026-57922?
To fix CVE-2026-57922, upgrade JetBrains YouTrack to version 2026.2.16593 or later.
4
What type of vulnerability is CVE-2026-57922?
CVE-2026-57922 is a project settings disclosure vulnerability that allows unauthorized access to settings via the MCP.
5
What is the risk level of CVE-2026-57922?
CVE-2026-57922 has a risk level rating of 17, categorized as low.