VYPR
Vypr IntelligenceAI-generatedSep 30, 2026· 22 CVEs

JetBrains YouTrack: 22 Vulnerabilities Disclosed, Ranging from Auth Bypass to Account Takeover

JetBrains patched 22 vulnerabilities in YouTrack, including critical flaws allowing account takeover and code execution, disclosed on September 30, 2026.

Key findings

  • 22 vulnerabilities disclosed in JetBrains YouTrack on September 30, 2026, patched in versions 2026.2.19197 and 2026.2.18991.
  • High-severity flaws include account takeover via notification signature replay (CVE-2026-100277) and arbitrary code execution via debugger bypass (CVE-2026-100273).
  • Multiple authorization bypass vulnerabilities allowed unauthorized access to comments, issues, and project settings.
  • Injection flaws include stored XSS, HTML injection, and SSRF via XHTML injection.
  • Credential exposure risks were present through integration URL manipulation and import configurations.

On September 30, 2026, JetBrains disclosed a significant batch of 22 vulnerabilities affecting its YouTrack issue tracker. These vulnerabilities, ranging in severity from Low to High, were all patched in version 2026.2.19197 and 2026.2.18991. The disclosures highlight a variety of security weaknesses, including authorization bypasses, cross-site scripting, and potential for account takeover.

Several vulnerabilities center on authorization flaws, allowing unauthorized users to access or modify sensitive information. For instance, CVE-2026-100278, a medium-severity flaw, permitted users with restricted permissions to edit and hide other users' comments. Similarly, CVE-2026-100271, a low-severity issue, enabled authenticated users to access information from other projects due to missing authorization on several endpoints. Project administrators also had elevated privileges in some cases, such as CVE-2026-100272, where they could read restricted issues via notification template previews, and CVE-2026-100268, allowing them to read comments from other projects using notification templates. Read-only users were not immune, with CVE-2026-100262 allowing them to overwrite project notification templates, and CVE-2026-100258 enabling them to read project settings.

Other notable vulnerabilities include those related to credential exposure and injection attacks. CVE-2026-100279, a medium-severity bug, allowed changing an integration URL to expose stored credentials. A similar credential disclosure was possible for low-level Admin Read permission users via import configurations in CVE-2026-100270. Security concerns also extended to injection flaws, such as CVE-2026-100275, a medium-severity stored XSS vulnerability in workflow error notifications, and CVE-2026-100267, a reDoS attack possibility via mailbox regex filters. Furthermore, CVE-2026-100263 involved stored HTML injection via the User-Agent header, and CVE-2026-100257 described an SSRF via stored XHTML injection during PDF export.

The batch also includes critical vulnerabilities with significant impact. CVE-2026-100277, a high-severity flaw, made account takeover possible by replaying a notification signature. Another high-severity vulnerability, CVE-2026-100273, involved an authorization bypass in the scripts debugger, potentially leading to arbitrary code execution.

JetBrains addressed these issues by releasing updated versions of YouTrack. Customers are advised to update to version 2026.2.19197 or 2026.2.18991, depending on the specific vulnerability, to mitigate these risks. The wide range of disclosed vulnerabilities underscores the importance of regular security updates for YouTrack users to protect against potential data breaches and unauthorized access.

The timely disclosure and patching of these vulnerabilities by JetBrains demonstrate a commitment to product security. Users should ensure their YouTrack instances are updated promptly to benefit from these security enhancements and prevent exploitation of the identified weaknesses.

CVE-2026-100280, CVE-2026-100279, CVE-2026-100278, CVE-2026-100277, CVE-2026-100276, CVE-2026-100275, CVE-2026-100274, CVE-2026-100273, CVE-2026-100272, CVE-2026-100271, CVE-2026-100270, CVE-2026-100269, CVE-2026-100268, CVE-2026-100267, CVE-2026-100264, CVE-2026-100263, CVE-2026-100262, CVE-2026-100261, CVE-2026-100260, CVE-2026-100259, CVE-2026-100258, CVE-2026-100257

AI-written article. Grounded in 22 CVE records listed below.