Insecure Default Initialization of Resource in YouTrack - CVE-2026-100260
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to authenticate after a password reset.
The vulnerability exists due to insecure default initialization of a resource in the mailbox integration when processing authentication requests after a password reset. A remote attacker can use the mailbox integration to authenticate after a password reset.