URL Exposure Vulnerability in JetBrains YouTrack
CVE-2026-100279

6.5MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-100279?

In JetBrains YouTrack prior to version 2026.2.19197, a vulnerability exists that allows an attacker to access stored credentials when the integration URL is changed. This security flaw highlights the importance of safeguarding sensitive data and ensuring that integration processes do not inadvertently expose user credentials.

Affected Version(s)

YouTrack 0 < 2026.2.19197

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.