CVE-2026-103494Medium· 6.6▾ SunlitIn JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86500Medium· 5.5In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
CVE-2026-86482High· 8.8In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
CVE-2026-103488High· 7.1In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVE-2026-103489Low· 2.0In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVE-2026-103490High· 7.2In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVE-2026-103491Medium· 6.5In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues