SB2026100229 - Multiple vulnerabilities in YouTrack



SB2026100229 - Multiple vulnerabilities in YouTrack

Published: October 2, 2026

Security Bulletin ID SB2026100229
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 30% Low 70%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2026-103493)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in a victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in Mermaid and LaTeX content rendering when rendering stored user-supplied Mermaid and LaTeX content. A remote user can store crafted Mermaid or LaTeX content to execute arbitrary script in a victim's browser.

User interaction is required for a victim to view the crafted content.


2) Infinite loop (CVE-ID: CVE-2026-103492)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a loop with an unreachable exit condition in PSD attachment processing when processing crafted PSD attachments. A remote attacker can submit a crafted PSD attachment to cause a denial of service.


3) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-103491)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose restricted issue information.

The vulnerability exists due to authorization bypass through user-controlled key in the issue activities API when handling requests for issue activities. A remote user can request activities for a restricted issue to disclose restricted issue information.


4) Missing Authorization (CVE-ID: CVE-2026-103490)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to missing authorization in user group links when manipulating user group links. A remote user can manipulate user group links to escalate privileges.


5) Cross-site scripting (CVE-ID: CVE-2026-103489)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to inject HTML into VCS command failure notifications.

The vulnerability exists due to improper neutralization of HTML input in VCS command failure notifications when rendering notification content. A remote attacker can cause a VCS command failure notification containing crafted HTML to be rendered to inject HTML into VCS command failure notifications.


6) Incorrect authorization (CVE-ID: CVE-2026-103488)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access restricted issues.

The vulnerability exists due to improper authorization in project team membership management when handling project team membership changes. A remote user can add themselves to project teams to access restricted issues.


7) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-103497)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause server-side requests to unintended destinations.

The vulnerability exists due to improper control of request destinations in the GitHub VCS integration when using the integration. A remote attacker can cause the integration to issue requests to unintended destinations to cause server-side requests to unintended destinations.


8) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-103496)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to read other users' notifications.

The vulnerability exists due to improper access control in inbox threads when accessing inbox threads using user-controlled identifiers. A remote user can manipulate an inbox thread identifier to read other users' notifications.


9) Missing Authorization (CVE-ID: CVE-2026-103495)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to reload translation catalogs.

The vulnerability exists due to missing authorization in the translation catalog reload functionality when accessing translation catalog reload functionality. A remote attacker can send a request to reload translation catalogs.


10) Incorrect Privilege Assignment (CVE-ID: CVE-2026-103494)

CWE-ID: CWE-266 - Incorrect Privilege Assignment

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to incorrect privilege assignment in user group membership changes when modifying user group memberships. A remote user can modify user group memberships to escalate privileges.


Remediation

Install update from vendor's website.