OCTOBER 2, 2026
Live Feed
Back to database
Case File

CVE-2026-103496

MEDIUM · CVSS 5.4

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-02

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.19422 are vulnerable to an Insecure Direct Object Reference (iDOR) in inbox threads, which allows unauthorized users to access and read notifications intended for other users. This vulnerability could lead to potential information disclosure, impacting user privacy and data confidentiality. Organizations using affected versions should prioritize remediation to safeguard sensitive user notifications.

CVE
CVE-2026-103496
Severity
MEDIUM
CVSS
5.4
EPSS
N/A

Original NVD Description

In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications

Related CVEs

Other vulnerabilities affecting the same vendor(s)