CVE-2026-100279Medium· 6.5▾ SunlitIn JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100257Medium· 4.3In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVE-2026-100277High· 8.9In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100276Medium· 5.9In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVE-2026-100274Medium· 6.5In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
CVE-2026-100278Medium· 4.9In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVE-2026-100280Low· 3.1In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible