CVE-2026-103491Medium· 6.5▾ SunlitIn JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
YouTrack < 2026.2.19422Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103496Medium· 5.4In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVE-2026-100272Medium· 4.9In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
CVE-2026-100268High· 7.7In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-86481Medium· 4.3In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
CVE-2026-86488Medium· 6.5In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
CVE-2026-86489Medium· 6.5In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations