Unauthorized Access to Project Comments in JetBrains YouTrack
CVE-2026-100268
7.7HIGH
What is CVE-2026-100268?
In JetBrains YouTrack, prior to version 2026.2.19197, an access control vulnerability exists that allows project administrators the unintended ability to read comments from other projects through notification templates. This flaw poses a significant risk by potentially exposing sensitive information and breaching project confidentiality.
Affected Version(s)
YouTrack 0 < 2026.2.19197