Authorization Flaw in JetBrains YouTrack Leads to Project Notification Template Overwrites
CVE-2026-100262
7.6HIGH
What is CVE-2026-100262?
In JetBrains YouTrack versions before 2026.2.18991, an authorization flaw has been identified that permits users with read-only access to projects to overwrite project notification templates. This issue raises concerns about project integrity and unauthorized modifications, potentially impacting communication and workflows if not addressed promptly.
Affected Version(s)
YouTrack 0 < 2026.2.18991