CVE Tools

Youtrack

147 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Youtrack, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Youtrack CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Youtrack CVEs per month
MonthCVEs
2024-1011
2024-110
2024-126
2025-012
2025-020
2025-030
2025-040
2025-052
2025-060
2025-072
2025-081
2025-090
2025-100
2025-113
2025-120
2026-010
2026-022
2026-030
2026-041
2026-055
2026-066
2026-073
2026-088
2026-0922

Severity

How the 147 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical117%
  • High3423%
  • Medium8759%
  • Low1510%

Latest CVEs

The 15 most recently published vulnerabilities affecting Youtrack.

  1. CVE-2026-86500In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin5.5
  2. CVE-2026-86499In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission4.3
  3. CVE-2026-86498In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission7.7
  4. CVE-2026-86496In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses4.3
  5. CVE-2026-86495In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects6.5
  6. CVE-2026-86497In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials6.8
  7. CVE-2026-86493In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards6.5
  8. CVE-2026-86492In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens8.5
  9. CVE-2026-86494In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues7.7
  10. CVE-2026-86489In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations6.5
  11. CVE-2026-86490In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint6.5
  12. CVE-2026-86491In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads3.5
  13. CVE-2026-86487In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content3.1
  14. CVE-2026-86488In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches6.5
  15. CVE-2026-86485In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks3.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store