Project Creation Flaw in JetBrains YouTrack Affects Custom Templates
CVE-2026-100280

3.1LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-100280?

A vulnerability in JetBrains YouTrack prior to version 2026.2.19197 allows users to create projects using unreadable custom templates. This issue highlights potential security risks that arise from improper handling of template readability, which could lead to inconsistencies or unforeseen errors during project initialization. Users of affected versions are advised to update to the latest release to mitigate potential exploitation and ensure robust project management.

Affected Version(s)

YouTrack 0 < 2026.2.19197

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.