CVE-2026-100272Medium· 4.9▾ SunlitIn JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100268High· 7.7In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-86481Medium· 4.3In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
CVE-2026-86488Medium· 6.5In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
CVE-2026-86489Medium· 6.5In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
CVE-2026-100277High· 8.9In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100279Medium· 6.5In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials