Missing Authorization in YouTrack - CVE-2026-100269
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote user to access Helpdesk project reporting functionality without authorization.
The vulnerability exists due to missing authorization in the Helpdesk project's Authorized Reporters list when enforcing reporter restrictions. A remote user can bypass the Authorized Reporters list to access Helpdesk project reporting functionality without authorization.