Privilege Escalation in JetBrains YouTrack by Restricted Users
CVE-2026-100278

4.9MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-100278?

In JetBrains YouTrack versions prior to 2026.2.19197, a significant vulnerability allows users with restricted permissions to edit and hide comments made by other users. This flaw may lead to unauthorized access and manipulation of user-generated content, potentially undermining trust and transparency within the application. Users and administrators are advised to review their access settings and upgrade to the latest version to mitigate this risk effectively.

Affected Version(s)

YouTrack 0 < 2026.2.19197

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.