Where
-Infinity
0
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues

First published (updated )
Severity
5.4
XSS
AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible

First published (updated )
Severity
7.2
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

First published (updated )
Severity
7.8
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects

First published (updated )
Severity
4.3
SSRF
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset

First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission

First published (updated )
Severity
7.6
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible

First published (updated )
Severity
2.7
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host

First published (updated )
Severity
6.5
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation

First published (updated )
Severity
7.7
AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address

First published (updated )
Severity
3.3
AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations

First published (updated )
Severity
2.7
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues

First published (updated )
Severity
9.8
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template

First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments

First published (updated )
Severity
6.5
SSRF
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials

First published (updated )
Severity
4.3
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible

First published (updated )
Severity
6.9
XSS
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible

First published (updated )
Severity
6.6
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes

First published (updated )
Severity
7.8
Code Injection
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible

First published (updated )
Severity
8.1
XSS
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203