In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications