OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100277

HIGH · CVSS 8.9 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.19197 are vulnerable to account takeover due to a flaw that allows attackers to replay notification signatures. This high-severity vulnerability (CVSS 8.9) can lead to unauthorized access to user accounts, potentially compromising sensitive project data. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-100277
Severity
HIGH
CVSS
8.9
EPSS
0.28%

Original NVD Description

In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature

Related CVEs

Other vulnerabilities affecting the same vendor(s)