| In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration CVE-2026-103497 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications CVE-2026-103496 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs CVE-2026-103495 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes CVE-2026-103494 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible CVE-2026-103493 | Severity high |
| In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments CVE-2026-103492 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues CVE-2026-103491 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links CVE-2026-103490 | Severity high |
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible CVE-2026-103489 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access… CVE-2026-103488 | Severity high |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible CVE-2026-100280 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials CVE-2026-100279 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments CVE-2026-100278 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature CVE-2026-100277 | Severity critical |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action CVE-2026-100276 | Severity high |
| In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible CVE-2026-100275 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template CVE-2026-100274 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution CVE-2026-100273 | Severity critical |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read… CVE-2026-100272 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from… CVE-2026-100271 | Severity low |
| In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import… CVE-2026-100270 | Severity low |
| In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed CVE-2026-100269 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates CVE-2026-100268 | Severity high |
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters CVE-2026-100267 | Severity medium |
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted… CVE-2026-100266 | Severity high |
| In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation CVE-2026-100265 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host CVE-2026-100264 | Severity low |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible CVE-2026-100263 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project… CVE-2026-100262 | Severity high |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission CVE-2026-100261 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset CVE-2026-100260 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access CVE-2026-100259 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings CVE-2026-100258 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export CVE-2026-100257 | Severity medium |
| In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects CVE-2026-100256 | Severity high |
| In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 administrator account takeover was possible via password reset CVE-2026-100255 | Severity critical |
| In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools CVE-2026-75060 | Severity high |
| In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible CVE-2026-75059 | Severity medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers CVE-2026-75058 | Severity medium |
| In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log CVE-2026-75057 | Severity medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible CVE-2026-75056 | Severity high |
| In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE CVE-2026-75055 | Severity medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects CVE-2026-75054 | Severity medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint CVE-2026-75053 | Severity medium |
| In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible CVE-2026-75051 | Severity high |
| In JetBrains YouTrack before 2026.1.13901,
2026.2.17950 doS attack was possible via crafted type parameters CVE-2026-75050 | Severity medium |
| In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles from other projects via the… CVE-2026-75049 | Severity medium |
| In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible CVE-2026-75048 | Severity high |
| In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint CVE-2026-75047 | Severity medium |
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint CVE-2026-75046 | Severity medium |
| In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via… CVE-2026-75045 | Severity critical |
| In JetBrains YouTrack before 2025.3.156085,
2026.1.13914,
2026.2.18095 missing authorisation allowed an authenticated user to delete… CVE-2026-75044 | Severity high |
| In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition CVE-2025-64457 | Severity high |
| In JetBrains Junie before… CVE-2025-58335 | Severity high |
| In JetBrains IDE Services before 2025.5.0.1086,
2025.4.2.2164 users without appropriate permissions could assign high-privileged role for… CVE-2025-58334 | Severity high |
| In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible CVE-2022-37009 | Severity high |