CVE-2026-100263Medium· 4.7▾ SunlitIn JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100275Medium· 6.9In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2026-86483Medium· 5.4In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVE-2026-86484Medium· 4.6In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
CVE-2026-86491Low· 3.5In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
CVE-2026-75048High· 8.2In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVE-2026-100277High· 8.9In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature