CyberRota Analysis
AI-GeneratedJetBrains YouTrack versions prior to 2026.2.19422 are vulnerable to an Insecure Direct Object Reference (iDOR) in inbox threads, which allows unauthorized users to access and read notifications intended for other users. This vulnerability could lead to potential information disclosure, impacting user privacy and data confidentiality. Organizations using affected versions should prioritize remediation to safeguard sensitive user notifications.
CVE
CVE-2026-103496
Severity
MEDIUM
CVSS
5.4
EPSS
N/A
Original NVD Description
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
Related CVEs
Other vulnerabilities affecting the same vendor(s)