Admin Permissions Flaw in JetBrains YouTrack Exposes Credentials
CVE-2026-100270

3.3LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-100270?

In JetBrains YouTrack versions before 2026.2.19197, a vulnerability exists that allows users with low-level Admin Read permissions to disclose sensitive integration credentials through improperly managed import configurations. This flaw highlights the importance of stringent access control measures to secure sensitive data within the application.

Affected Version(s)

YouTrack 0 < 2026.2.19197

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.