Known Vulnerabilities for Youtrack by Jetbrains
Listed below are 10 of the newest known vulnerabilities associated with "Youtrack" by "Jetbrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100280 json | In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100279 json | In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100278 json | In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100277 json | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-100276 json | In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the act... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100275 json | In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100274 json | In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100273 json | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-100272 json | In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administ... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100271 json | In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access in... | Not Provided | 2026-09-30 | 2026-09-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Youtrack | 7.0.29566 | |||
| Application | Jetbrains | Youtrack | 7.0.28958 | |||
| Application | Jetbrains | Youtrack | 7.0.28450 | |||
| Application | Jetbrains | Youtrack | 7.0.28110 | |||
| Application | Jetbrains | Youtrack | 7.0.27965 | |||
| Application | Jetbrains | Youtrack | 7.0.27777 | |||
| Application | Jetbrains | Youtrack | 7.0.27705 | |||
| Application | Jetbrains | Youtrack | 7.0.27676 | |||
| Application | Jetbrains | Youtrack | 7.0.26927 | |||
| Application | Jetbrains | Youtrack | 7.0.26754 | |||
| Application | Jetbrains | Youtrack | 7.0.26630 | |||
| Application | Jetbrains | Youtrack | 7.0.26198 | |||
| Application | Jetbrains | Youtrack | 6.5.17122 | |||
| Application | Jetbrains | Youtrack | 6.5.17105 | |||
| Application | Jetbrains | Youtrack | 6.5.17057 | |||
| Application | Jetbrains | Youtrack | 6.5.17031 | |||
| Application | Jetbrains | Youtrack | 6.0.12634 | |||
| Application | Jetbrains | Youtrack | 6.0.12124 | |||
| Application | Jetbrains | Youtrack | 5.2.5 | |||
| Application | Jetbrains | Youtrack | 4.2.4 |