Prototype Pollution Vulnerability in JetBrains YouTrack
CVE-2026-57926

2.6LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-57926?

A vulnerability in JetBrains YouTrack, prior to version 2026.2.16593, allows attackers to exploit the websandbox bridge, potentially leading to prototype pollution attacks. This can enable unauthorized access and unauthorized modification of object prototypes, which may compromise the integrity and security of applications relying on the affected version. Mitigating this risk involves updating to a patched version of YouTrack.

Affected Version(s)

YouTrack 0 < 2026.2.16593

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.