| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 administrator account takeover was possible via password reset |
| In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings |
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access |
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible |
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host |
| In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation |
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address |
| In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues |
| In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution |
| In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments |